Impact
An unauthenticated attacker can forge a share invitation that, when clicked by a logged‑in recipient, executes stored cross‑site scripting within the Zimbra Modern Web Client. This script runs with the victim’s browser privileges, enabling the attacker to read mailbox contents and perform actions as the legitimate user, effectively creating a session hijack. The weakness is a classic stored XSS (CWE‑79) that grants full read/write access to the victim’s mailbox data.
Affected Systems
The vulnerability affects the Zimbra Collaboration Suite (ZCS) Modern Web Client in all deployed versions, as no specific product version range was identified in the advisory. Any installation that serves the modern web interface is potentially impacted.
Risk and Exploitability
The CVSS score of 9.3 indicates a high‑severity risk. Attackers need only to deliver a forged link to a user who has recently logged into Zimbra; no prior authentication is required. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high impact score and plausible attack vector suggest that exploitation is likely if no mitigations are applied.
OpenCVE Enrichment