Vulnerability record · CVE-2022-24682 · published 9 February 2022
CVE-2022-24682: Zimbra Collaboration Suite Calendar stored XSS via unescaped HTML attributes
SSynacor · Zimbra Collaboration Suite
The Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1) fails to escape HTML placed inside element attributes, allowing arbitrary markup and executable JavaScript to be injected into the rendered document. This is a stored cross-site scripting flaw that was exploited in the wild starting December 2021, making it a real-world email-borne attack against webmail users.
Description
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityIt is a KEV-listed, actively exploited zero-day with known ransomware campaign use, though the CVSS base score is only 6.1 and exploitation requires user interaction.
What it is
The Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1) fails to escape HTML placed inside element attributes, allowing arbitrary markup and executable JavaScript to be injected into the rendered document. This is a stored cross-site scripting flaw that was exploited in the wild starting December 2021, making it a real-world email-borne attack against webmail users.
Impact
An attacker can execute JavaScript in the context of a victim's Zimbra webmail session, enabling theft of session data or credentials and other actions performed as the victim. Because the injected content is stored in the Calendar, the payload can trigger whenever the affected content is viewed.
Attack surface
Reachable over the network through the Zimbra webmail Calendar interface; the CVSS vector indicates no privileges are required but user interaction is needed, meaning the victim must view the crafted calendar content. No authentication is required to deliver the malicious markup, though the victim must be logged into Zimbra to be affected.
Exploitation
Exploitation is confirmed: CISA added this to the Known Exploited Vulnerabilities catalog on 2022-02-25 with a due date of 2022-03-11, and it is flagged as used in known ransomware campaigns. EPSS gives a 30-day probability of 0.30931 (98.165th percentile), and references include an exploit-tagged third-party advisory describing active zero-day exploitation.
What to do
- Apply the vendor hotfix and upgrade Zimbra Collaboration Suite to 8.8.15 patch 30 (update 1) or later as directed by the vendor advisories.
- If immediate patching is not possible, restrict or disable the Calendar feature for untrusted users until the fix is applied.
- Review the vendor Security Center and release notes for any additional hardening guidance tied to this hotfix.
- Treat this as a KEV-listed issue and prioritize remediation within the CISA due date; verify no prior compromise before closing it out.
Detection
- Hunt Zimbra web and application logs for calendar items containing HTML or JavaScript in element attributes, especially unexpected script or event-handler patterns.
- Monitor for anomalous outbound requests or session activity originating from Zimbra webmail clients that could indicate script execution or data exfiltration.
- Review mail and calendar content for suspicious HTML payloads delivered to Zimbra users around the December 2021 onward exploitation window.
- Check for signs of prior compromise on Zimbra hosts, including unexpected processes, web shells, or credential access activity, given the KEV ransomware association.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-24682 to the Known Exploited Vulnerabilities catalog on 25 February 2022 as "Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 11 March 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-24682 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-24682), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.