CVE-2024-45517: Synacor Zimbra Collaboration Suite
Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.
An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability in the /h/rest endpoint of the Zimbra webmail and admin panel interfaces allows attackers to execute arbitrary JavaScript in the victim's session. This issue is caused by improper sanitization of user input, leading to potential compromise of sensitive information. Exploitation requires user interaction to access the malicious URL.
Affected products
- Synacor Zimbra Collaboration Suite: before 8.8.15 (fixed in 8.8.15); from 10.0.0, before 10.0.9 (fixed in 10.0.9); version 8.8.15 only; version 9.0.0 only; version 10.1.1 only
Published 2024-11-21. Last modified 2026-06-17.