PT-2022-4547 · Zimbra · Zimbra Collaboration Suite

Steven Adair

+1

·

Published

2022-02-09

·

Updated

2025-11-04

·

CVE-2022-24682

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration Suite versions 8.8.x through 8.8.15 patch 29
Description An issue was discovered in the Calendar feature, allowing an attacker to place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document. The issue has been exploited in the wild starting in December 2021.
Recommendations For Zimbra Collaboration Suite versions 8.8.x through 8.8.15 patch 29, update to version 8.8.15 patch 30 (update 1) to resolve the issue. As a temporary workaround, consider restricting access to the Calendar feature until a patch is available. Avoid using the Calendar feature with untrusted input until the issue is resolved.

Exploit

Fix

Improper Encoding or Escaping of Output

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-05422
CVE-2022-24682

Affected Products

Zimbra Collaboration Suite