Vulnerability record · CVE-2024-27443 · published 12 August 2024
CVE-2024-27443: Zimbra webmail classic calendar invite XSS via crafted header
Zimbra · Collaboration
Zimbra Collaboration 9.0 and 10.0 fail to properly validate the calendar header in the CalendarInvite feature of the classic webmail interface, allowing a stored/reflected XSS payload to be embedded in an email. When the victim opens the message in the classic UI, the script runs in their session context, which matters because webmail sessions hold mail and calendar data and are a known target for credential and token theft.
Description
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityIt is in CISA KEV with a high EPSS percentile, but exploitation requires the victim to view the message in the classic UI and the CVSS base is only 6.1.
What it is
Zimbra Collaboration 9.0 and 10.0 fail to properly validate the calendar header in the CalendarInvite feature of the classic webmail interface, allowing a stored/reflected XSS payload to be embedded in an email. When the victim opens the message in the classic UI, the script runs in their session context, which matters because webmail sessions hold mail and calendar data and are a known target for credential and token theft.
Impact
An attacker can execute arbitrary JavaScript in the victim's authenticated Zimbra session, enabling session or token theft, mailbox and calendar data access, and actions performed as the victim. The CVSS scope change (S:C) reflects that the impact can extend beyond the vulnerable component.
Attack surface
Reached remotely over the network by sending an email with a crafted calendar header; no authentication is required for the sender, but the victim must view the message in the Zimbra webmail classic interface (UI:R).
Exploitation
CVE-2024-27443 is listed in CISA KEV (added 2025-05-19, no known ransomware use) and has a high EPSS 30-day probability of 0.23632 (97.7th percentile), indicating observed exploitation and elevated likelihood. References include vendor release notes and ESET research coverage of Operation Roundpress.
What to do
- Apply the vendor security fixes in Zimbra 10.0.7 and 9.0.0 P39 (or later) immediately.
- Follow CISA KEV required action and BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable.
- Restrict or migrate users off the classic webmail interface where feasible, since the flaw is specific to it.
- Enforce phishing-resistant MFA and short session lifetimes to limit the value of any stolen session.
- Filter or strip crafted calendar headers and active content at the mail gateway as a compensating control.
Detection
- Hunt mail logs and gateway records for inbound messages with unusual or malformed calendar header fields.
- Monitor Zimbra webmail and proxy logs for anomalous JavaScript-bearing requests or unexpected outbound calls from client sessions.
- Review authentication and session logs for token reuse, impossible-travel logins, or new session creation following calendar invite views.
- Search endpoint and browser telemetry for script execution originating from Zimbra webmail pages.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-27443 to the Known Exploited Vulnerabilities catalog on 19 May 2025 as "Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 9 June 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.7#Security_Fixes | Release Notes |
| https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P39#Security_Fixes | Release Notes |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-27443 | US Government Resource |
| https://www.welivesecurity.com/en/eset-research/operation-roundpress/ | Press/Media Coverage |
Track CVE-2024-27443 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-27443), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.