---
id: CVE-2022-24682
title: >-
  An issue was discovered in the Calendar feature in Zimbra Collaboration Suite
  8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in
  December 2021
summary: >-
  An issue was discovered in the Calendar feature in Zimbra Collaboration Suite
  8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in
  December 2021. An attacker could place HTML containing executable JavaScript
  insi…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-116
  - CWE-116
vendor: synacor
product: zimbra_collaboration_suite
affected:
  - 'zimbra_collaboration_suite >= 8.8.0, < 8.8.15'
  - zimbra_collaboration_suite = 8.8.15
patched:
  - zimbra_collaboration_suite 8.8.15
published: '2022-02-09'
updated: '2026-08-06'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-24682'
references:
  - url: >-
      https://blog.zimbra.com/2022/02/hotfix-available-5-feb-for-zero-day-exploit-vulnerability-in-zimbra-8-8-15/
    label: cve@mitre.org
  - url: 'https://wiki.zimbra.com/wiki/Security_Center'
    label: cve@mitre.org
  - url: 'https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P30'
    label: cve@mitre.org
  - url: 'https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories'
    label: cve@mitre.org
  - url: >-
      https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitation-of-zero-day-xss-vulnerability-in-zimbra/
    label: cve@mitre.org
  - url: >-
      https://blog.zimbra.com/2022/02/hotfix-available-5-feb-for-zero-day-exploit-vulnerability-in-zimbra-8-8-15/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://wiki.zimbra.com/wiki/Security_Center'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P30'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitation-of-zero-day-xss-vulnerability-in-zimbra/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-24682
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.30931
epssPercentile: 0.98221
kev: true
kevDateAdded: '2022-02-25'
kevDueDate: '2022-03-11'
kevRansomware: true
exploited: true
zeroDay: true
ingestedAt: '2026-08-06T05:56:20.433Z'
exploits:
  nuclei:
    - CVE-2022-24682
  checkedAt: '2026-09-21T15:25:12.409Z'
exploitAvailable: true
---

## Overview

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.

## Affected

- `zimbra_collaboration_suite >= 8.8.0, < 8.8.15`
- `zimbra_collaboration_suite = 8.8.15`

## Remediation

Upgrade past the affected range:

- `zimbra_collaboration_suite 8.8.15`
