Stored Cross-Site Scripting Vulnerability in Zimbra Collaboration Products
CVE-2025-27915

5.4MEDIUM

Key Information:

Vendor

Zimbra

Vendor
CVE Published:
12 March 2025

What is CVE-2025-27915?

A stored cross-site scripting (XSS) vulnerability was identified in the Classic Web Client of Zimbra Collaboration Server versions 9.0, 10.0, and 10.1. This security flaw arises from inadequate sanitization of HTML content found within ICS files. When users access an email containing a malicious ICS entry, embedded JavaScript is executed through an ontoggle event in a tag. This exploitation can allow attackers to execute arbitrary JavaScript within the victim's session, facilitating unauthorized actions such as redirecting emails and exfiltrating sensitive data. Prompt remediation is critical to mitigate potential risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.