CVE-2022-24682Medium· 6.1▾ Midnight⚠ Exploited in the wild0dayPoC availableAn issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript insi…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 33.6 · likelihood 6.2 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Mar 11, 2022
Last analysed / modified upstream
31%
Nuclei ×1
Added to the CISA catalog on Feb 25, 2022. Federal remediation due Mar 11, 2022. View catalog ↗
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.
zimbra_collaboration_suite >= 8.8.0, < 8.8.15zimbra_collaboration_suite = 8.8.15Upgrade past the affected range:
zimbra_collaboration_suite 8.8.15Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-41352Critical· 9.8An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0
CVE-2022-37042Critical· 9.8Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it
CVE-2022-27925High· 7.2Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it
CVE-2022-27924High· 7.5Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance
CVE-2026-73570High· 8.9A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled
CVE-2018-6882Medium· 6.1Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTM…