PT-2024-10389 · Zimbra · Zimbra Collaboration Suite
Published
2024-09-01
·
Updated
2025-06-11
·
CVE-2024-45512
5.5
Medium
Base vector | Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Zimbra Collaboration Suite (ZCS) versions through 10.1
Description:
The issue exists due to inadequate protection of the web page structure in the Briefcase Module of the Zimbra Collaboration Suite (ZCS). An attacker can exploit this by creating a folder in the Briefcase module with a malicious payload and sharing it with a victim. When the victim interacts with the folder share notification, the malicious script executes in their browser, leading to unauthorized actions within the victim's session. This is a stored Cross-Site Scripting (XSS) vulnerability.
Recommendations:
For Zimbra Collaboration Suite (ZCS) versions through 10.1, update to Zimbra Daffodil (v10.1.1) or later to fix the Stored Cross-Site Scripting (XSS) vulnerability in the Briefcase module.
As a temporary workaround, consider restricting access to the Briefcase module until a patch is applied.
Fix
XSS
Weakness Enumeration
Related Identifiers
Affected Products
References · 14
- https://wiki.zimbra.com/wiki/Security_Center · Vendor Advisory
- https://bdu.fstec.ru/vul/2025-00898 · Security Note
- https://osv.dev/vulnerability/CVE-2024-45512 · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45512 · Security Note
- https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P41#Security_Fixes · Note
- https://twitter.com/VulmonFeeds/status/1838251220995022900 · Twitter Post
- https://twitter.com/CVEnew/status/1859677189974917185 · Twitter Post
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.1#Security_Fixes · Note
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.9#Security_Fixes · Note
- https://t.me/cvenotify/125449 · Telegram Post
- https://cybersecurity-help.cz/vulnerabilities/96810 · Note
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45512 · Note
- https://cybersecurity-help.cz/vdb/SB2024090468 · Note
- https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy · Note