CVE-2022-24682
בינונית 6.1 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.
מדדים
- CVSS 3.1
-
6.1 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 31% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-116
מוצרים מושפעים
synacor: zimbra collaboration suite
קישורים
- https://blog.zimbra.com/2022/02/hotfix-available-5-feb-for-zero-day-exploit-vu… Vendor Advisory
- https://wiki.zimbra.com/wiki/Security_Center Vendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P30 Release NotesVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories Vendor Advisory
- https://blog.zimbra.com/2022/02/hotfix-available-5-feb-for-zero-day-exploit-vu… Vendor Advisory
- https://wiki.zimbra.com/wiki/Security_Center Vendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P30 Release NotesVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories Vendor Advisory
- https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitat… ExploitThird Party Advisory
- https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitat… ExploitThird Party Advisory