Stored Cross-Site Scripting Vulnerability in Zimbra Collaboration Products
CVE-2025-27915
5.4MEDIUM
What is CVE-2025-27915?
A stored cross-site scripting (XSS) vulnerability was identified in the Classic Web Client of Zimbra Collaboration Server versions 9.0, 10.0, and 10.1. This security flaw arises from inadequate sanitization of HTML content found within ICS files. When users access an email containing a malicious ICS entry, embedded JavaScript is executed through an ontoggle event in a tag. This exploitation can allow attackers to execute arbitrary JavaScript within the victim's session, facilitating unauthorized actions such as redirecting emails and exfiltrating sensitive data. Prompt remediation is critical to mitigate potential risks associated with this vulnerability.