← Vulnerability feed

Vulnerability record · CVE-2024-27443 · published 12 August 2024

CVE-2024-27443: Zimbra webmail classic calendar invite XSS via crafted header

Zimbra · Collaboration

Zimbra Collaboration 9.0 and 10.0 fail to properly validate the calendar header in the CalendarInvite feature of the classic webmail interface, allowing a stored/reflected XSS payload to be embedded in an email. When the victim opens the message in the classic UI, the script runs in their session context, which matters because webmail sessions hold mail and calendar data and are a known target for credential and token theft.

6.1 CVSS 3.1 Medium CISA KEV since 19 May 2025 EPSS 24% · top 2.3% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
24%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is in CISA KEV with a high EPSS percentile, but exploitation requires the victim to view the message in the classic UI and the CVSS base is only 6.1.

What it is

Zimbra Collaboration 9.0 and 10.0 fail to properly validate the calendar header in the CalendarInvite feature of the classic webmail interface, allowing a stored/reflected XSS payload to be embedded in an email. When the victim opens the message in the classic UI, the script runs in their session context, which matters because webmail sessions hold mail and calendar data and are a known target for credential and token theft.

Impact

An attacker can execute arbitrary JavaScript in the victim's authenticated Zimbra session, enabling session or token theft, mailbox and calendar data access, and actions performed as the victim. The CVSS scope change (S:C) reflects that the impact can extend beyond the vulnerable component.

Attack surface

Reached remotely over the network by sending an email with a crafted calendar header; no authentication is required for the sender, but the victim must view the message in the Zimbra webmail classic interface (UI:R).

Exploitation

CVE-2024-27443 is listed in CISA KEV (added 2025-05-19, no known ransomware use) and has a high EPSS 30-day probability of 0.23632 (97.7th percentile), indicating observed exploitation and elevated likelihood. References include vendor release notes and ESET research coverage of Operation Roundpress.

What to do

  • Apply the vendor security fixes in Zimbra 10.0.7 and 9.0.0 P39 (or later) immediately.
  • Follow CISA KEV required action and BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable.
  • Restrict or migrate users off the classic webmail interface where feasible, since the flaw is specific to it.
  • Enforce phishing-resistant MFA and short session lifetimes to limit the value of any stolen session.
  • Filter or strip crafted calendar headers and active content at the mail gateway as a compensating control.

Detection

  • Hunt mail logs and gateway records for inbound messages with unusual or malformed calendar header fields.
  • Monitor Zimbra webmail and proxy logs for anomalous JavaScript-bearing requests or unexpected outbound calls from client sessions.
  • Review authentication and session logs for token reuse, impossible-travel logins, or new session creation following calendar invite views.
  • Search endpoint and browser telemetry for script execution originating from Zimbra webmail pages.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-27443 to the Known Exploited Vulnerabilities catalog on 19 May 2025 as "Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 9 June 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-27443 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-29381Zimbra collaboration incorrect authorization vulnerabilityAn issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sensitive information via the pa…EPSS 1.0%9.8CVE-2023-29382Zimbra collaboration code injection vulnerabilityAn issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preauth.jsp component.EPSS 1.0%9.8CVE-2022-32294Zimbra collaboration incorrect authorization vulnerabilityZimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command). It is visible i…EPSS 2.6%9.8CVE-2021-35209Zimbra collaboration server-side request forgery (ssrf) vulnerabilityAn issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9.0.0 Patc…EPSS 3.0%8.8CVE-2024-45518Zimbra collaboration server-side request forgery (ssrf) vulnerabilityAn issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. …EPSS 21%8.8CVE-2023-34193Zimbra collaboration unrestricted file upload vulnerabilityFile Upload vulnerability in Zimbra ZCS 8.8.15 allows an authenticated privileged user to execute arbitrary code and obtain sensitive information via…EPSS 1.2%7.8CVE-2024-27442Zimbra collaboration improper privilege management vulnerabilityAn issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is intended to be executed by the z…EPSS 0.35%7.8CVE-2023-24032Zimbra collaboration command injection vulnerabilityIn Zimbra Collaboration Suite through 9.0 and 8.8.15, an attacker (who has initial user access to a Zimbra server instance) can execute commands as r…EPSS 0.96%

Source: NIST National Vulnerability Database (record CVE-2024-27443), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.