MEDIUM

CVE-2025-66376

Synacor Zimbra Collaboration Suite 2026-01-05 CVSS v3.1
CVSS
6.1
KEV

Description

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

Summary dbcve.org

Zimbra Collaboration (ZCS) versions 10 before 10.0.18 and 10.1 before 10.1.13 contain a stored XSS vulnerability in the Classic UI. Attackers can embed malicious CSS @import directives within HTML email messages. When recipients view these emails in the Classic UI, the CSS @import can load external resources or potentially execute JavaScript, allowing session hijacking, credential theft, or arbitrary actions in the context of the user's session.

Mitigation

Upgrade ZCS to version 10.0.18, 10.1.13, or later. As a temporary workaround, users can switch to the Modern UI or disable HTML email rendering in the Classic UI.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

19.56%
Probability of exploitation in next 30 days
97.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE