← Vulnerability feed

Vulnerability record · CVE-2022-24682 · published 9 February 2022

CVE-2022-24682: Zimbra Collaboration Suite Calendar stored XSS via unescaped HTML attributes

SSynacor · Zimbra Collaboration Suite

The Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1) fails to escape HTML placed inside element attributes, allowing arbitrary markup and executable JavaScript to be injected into the rendered document. This is a stored cross-site scripting flaw that was exploited in the wild starting December 2021, making it a real-world email-borne attack against webmail users.

6.1 CVSS 3.1 Medium CISA KEV since 25 Feb 2022 Known ransomware use EPSS 31% · top 1.8% CWE-116 · CWE-116
6.1CVSS 3.1 base score, v2 4.3
31%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
11References, 2 tagged exploit
7 Aug 2026Last modified by NVD

Description

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is a KEV-listed, actively exploited zero-day with known ransomware campaign use, though the CVSS base score is only 6.1 and exploitation requires user interaction.

What it is

The Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1) fails to escape HTML placed inside element attributes, allowing arbitrary markup and executable JavaScript to be injected into the rendered document. This is a stored cross-site scripting flaw that was exploited in the wild starting December 2021, making it a real-world email-borne attack against webmail users.

Impact

An attacker can execute JavaScript in the context of a victim's Zimbra webmail session, enabling theft of session data or credentials and other actions performed as the victim. Because the injected content is stored in the Calendar, the payload can trigger whenever the affected content is viewed.

Attack surface

Reachable over the network through the Zimbra webmail Calendar interface; the CVSS vector indicates no privileges are required but user interaction is needed, meaning the victim must view the crafted calendar content. No authentication is required to deliver the malicious markup, though the victim must be logged into Zimbra to be affected.

Exploitation

Exploitation is confirmed: CISA added this to the Known Exploited Vulnerabilities catalog on 2022-02-25 with a due date of 2022-03-11, and it is flagged as used in known ransomware campaigns. EPSS gives a 30-day probability of 0.30931 (98.165th percentile), and references include an exploit-tagged third-party advisory describing active zero-day exploitation.

What to do

  • Apply the vendor hotfix and upgrade Zimbra Collaboration Suite to 8.8.15 patch 30 (update 1) or later as directed by the vendor advisories.
  • If immediate patching is not possible, restrict or disable the Calendar feature for untrusted users until the fix is applied.
  • Review the vendor Security Center and release notes for any additional hardening guidance tied to this hotfix.
  • Treat this as a KEV-listed issue and prioritize remediation within the CISA due date; verify no prior compromise before closing it out.

Detection

  • Hunt Zimbra web and application logs for calendar items containing HTML or JavaScript in element attributes, especially unexpected script or event-handler patterns.
  • Monitor for anomalous outbound requests or session activity originating from Zimbra webmail clients that could indicate script execution or data exfiltration.
  • Review mail and calendar content for suspicious HTML payloads delivered to Zimbra users around the December 2021 onward exploitation window.
  • Check for signs of prior compromise on Zimbra hosts, including unexpected processes, web shells, or credential access activity, given the KEV ransomware association.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-24682 to the Known Exploited Vulnerabilities catalog on 25 February 2022 as "Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 11 March 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-24682 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-45519Zimbra Collaboration postjournal service unauthenticated command executionThe postjournal service in Zimbra Collaboration Suite fails to properly neutralize input, allowing OS command injection. Because the service can be r…KEVEPSS 100%analysed9.8CVE-2022-41352Zimbra Collaboration amavis cpio path traversal arbitrary file uploadZimbra Collaboration Suite 8.8.15 and 9.0 allow an attacker to upload arbitrary files through amavis by abusing cpio archive extraction into the web-…KEVEPSS 95%analysed9.8CVE-2022-37042Zimbra Collaboration Suite mboximport auth bypass path traversal RCEZimbra Collaboration Suite 8.8.15 and 9.0 mboximport accepts a ZIP archive and extracts files without requiring an authtoken, allowing unauthenticate…KEVEPSS 92%analysed9.8CVE-2020-7796Zimbra Collaboration Suite WebEx zimlet SSRFZimbra Collaboration Suite before 8.8.15 Patch 7 is vulnerable to server-side request forgery when the WebEx zimlet is installed and its JSP is enabl…KEVEPSS 84%analysed9.8CVE-2019-9670Zimbra mailboxd Autodiscover XXE allows unauthenticated compromiseThe mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 parses XML in the Autodiscover servlet without restricting extern…KEVEPSS 100%analysed9.0CVE-2023-34192Zimbra ZCS autoSaveDraft XSS enables remote code executionZimbra Collaboration Suite 8.8.15 has a cross-site scripting flaw in the /h/autoSaveDraft function. A remote authenticated attacker can inject a craf…KEVEPSS 77%analysed8.9CVE-2026-73570Zimbra Collaboration SNMP notification OS command injectionZimbra Collaboration Suite before 10.1.20 contains an OS command injection flaw in SNMP notification processing when the optional zimbra-snmp package…KEVEPSS 12%analysed8.8CVE-2025-68645Zimbra Webmail Classic UI RestFilter local file inclusionZimbra Collaboration Suite 10.0 and 10.1 mishandle user-supplied parameters in the RestFilter servlet of the Webmail Classic UI, allowing local file …KEVEPSS 49%analysed

Source: NIST National Vulnerability Database (record CVE-2022-24682), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.