CVE-2025-66376
בינונית 6.1 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
מדדים
- CVSS 3.1
-
6.1 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 22% (אחוזון 100) נכון ל-26/7/2026
- CWE
- CWE-79
מוצרים מושפעים
synacor: zimbra collaboration suite
קישורים
- https://wiki.zimbra.com/wiki/Security_Center Release NotesVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories Vendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.18#Security_Fixes Release Notes
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.13#Security_Fixes Release Notes
- https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy Product
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource