Impact
An unauthenticated sender can forge a share notification that embeds malicious script code. When a signed‑in user clicks “Accept Share”, the Classic Web Client stores and executes the script, allowing the attacker to read mailbox data and impersonate the user. The vulnerability is a classic stored XSS flaw (CWE‑79) that can lead to data theft and credential compromise.
Affected Systems
The flaw impacts all installations of the Zimbra Collaboration Suite Classic Web Client that enable the share invitation feature. No specific software version ranges are listed, so every deployed instance is potentially vulnerable until a vendor release containing the fix is applied.
Risk and Exploitability
The CVSS score is 9.3, reflecting a high‑severity compromise vector. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly documented exploit yet. Attackers do not need to authenticate and only require that a victim opens the forged share link, which is likely to happen if users are not cautious. The risk is therefore significant for any organization using Zimbra Classic without the latest security update.
OpenCVE Enrichment