CVE-2025-66376
Description
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
Summary dbcve.org
Zimbra Collaboration (ZCS) versions 10 before 10.0.18 and 10.1 before 10.1.13 contain a stored XSS vulnerability in the Classic UI. Attackers can embed malicious CSS @import directives within HTML email messages. When recipients view these emails in the Classic UI, the CSS @import can load external resources or potentially execute JavaScript, allowing session hijacking, credential theft, or arbitrary actions in the context of the user's session.
Mitigation
Upgrade ZCS to version 10.0.18, 10.1.13, or later. As a temporary workaround, users can switch to the Modern UI or disable HTML email rendering in the Classic UI.