Impact
The vulnerability is a stored XSS in the Zimbra Classic Web Client. When a user previews an attachment that contains specially crafted content, the browser executes arbitrary JavaScript in the context of the victim’s session. This allows the attacker to perform unauthorized actions on behalf of the victim, such as altering data, exfiltrating sensitive information, or executing further malicious code. The weakness is a classic cross‑site scripting flaw (CWE‑79).
Affected Systems
Zimbra Collaboration Suite (ZCS) versions prior to 10.1.17 are vulnerable. Any system that hosts or serves Zimbra Classic Web Client and accepts user‑supplied email attachments is at risk. No specific product sub‑versions are listed beyond the major release.
Risk and Exploitability
The CVSS base score of 6.1 indicates a medium severity. The EPSS score is not available, so the current likelihood of exploitation is uncertain, but the vulnerability is not yet catalogued in the CISA KEV list. The most probable attack vector is remote delivery of a malicious email containing an attachment that a victim views in their browser. If the inline preview feature is enabled, the attacker can trigger the payload simply by having the victim preview the attachment, without the need for additional user interaction beyond opening the message.
OpenCVE Enrichment