Reflected Cross-Site Scripting Vulnerability in Zimbra Collaboration
CVE-2025-27914
5.4MEDIUM
What is CVE-2025-27914?
A Reflected Cross-Site Scripting vulnerability has been identified in Zimbra Collaboration versions 9.0, 10.0, and 10.1. This flaw is present at the /h/rest endpoint, enabling authenticated attackers to inject malicious JavaScript into user sessions through crafted URLs. Exploitation involves the use of a valid authentication token and manipulation of query parameters to trigger the vulnerability when accessed by unsuspecting victims.