CVE-2022-24682
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Feb 25, 2022
- US federal agencies must remediate it by Mar 11, 2022 (BOD 22-01)
- Attacked 55 days before the vulnerability was made public
- Used in ransomware campaigns
Apply updates per vendor instructions.
Source: CISA KEV · Apr 24, 2024 Nov 7, 2023 Oct 21, 2023 Oct 5, 2023 Aug 3, 2023 Mar 20, 2023
CVSS score6.1 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NWeakness type (CWE)CWE-116, CWE-116
Vendorssynacor
Affected products
| Vendors | Product | Versions |
|---|---|---|
| synacor | zimbra collaboration suite | < 8.8.15 |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
