PT-2024-8655 · Zimbra · Zimbra Collaboration

Published

2024-09-23

·

Updated

2025-06-11

·

CVE-2024-45511

CVSS v2.0

9.7

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration (ZCS) versions through 10.1
Description A reflected Cross-Site Scripting (XSS) issue exists in the Briefcase module due to improper sanitization of file content by the OnlyOffice formatter. This occurs when the victim opens a crafted URL pointing to a shared folder containing a malicious file uploaded by the attacker, allowing the attacker to execute arbitrary JavaScript in the context of the victim's session.
Recommendations For versions through 10.1, consider updating to Zimbra Daffodil (v10.1.1) or later, which includes a patch for the reflected XSS vulnerability in the Briefcase module. As a temporary workaround, consider disabling the Briefcase module or restricting access to shared folders until a patch is applied. Avoid opening crafted URLs pointing to shared folders containing potentially malicious files.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-10247
CVE-2024-45511

Affected Products

Zimbra Collaboration