CVE-2022-24682

Medium6.1Published on February 9, 2022

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since Feb 25, 2022
  • US federal agencies must remediate it by Mar 11, 2022 (BOD 22-01)
  • Attacked 55 days before the vulnerability was made public
  • Used in ransomware campaigns

Apply updates per vendor instructions.

Source: CISA KEV · Apr 24, 2024 Nov 7, 2023 Oct 21, 2023 Oct 5, 2023 Aug 3, 2023 Mar 20, 2023

CVSS score6.1 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness type (CWE)CWE-116, CWE-116
Vendorssynacor

Affected products

VendorsProductVersions
synacorzimbra collaboration suite< 8.8.15

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database