CyberSec.Space Logo
CVEブラウザに戻る

CVE-2024-27443

🔥 Known Exploited (CISA KEV)MEDIUM
6.1
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2024-08-12
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.

Affected Platforms (CPE)

📦
Zimbra

Collaboration

>= 10.0.0 and < 10.0.7= 9.0.0

References & Advisories

関連する脆弱性情報