SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2022-24682

Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability

KEVMEDIUM 6.1EPSS 30.9%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 11 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
30.93% probability · 98th percentile
CISA KEV
Listed 25 February 2022 · due 11 March 2022 · used in ransomware campaigns
Weakness
CWE-116
Affected
synacor/zimbra collaboration suite
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2022-24682

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.