Zimbra Collaboration Cross-Site Scripting Vulnerability in Webmail Briefcase Import

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Zimbra Collaboration (ZCS) versions through 10.1. This issue arises from inadequate validation of content type metadata when files are imported into the briefcase, allowing attackers to execute arbitrary JavaScript in the victim's session. The vulnerability can be exploited by crafting a file with manipulated metadata to bypass content type checks.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected JavaScript is executed in the context of the user.

Reproduction

To reproduce this vulnerability, import a file with altered metadata into the Zimbra webmail briefcase. The file should be crafted to exploit the lack of content type validation, enabling the execution of JavaScript in the user's session.

Remediation

Users can upgrade to ZCS versions 10.1.1, 10.0.9 Patch 41, or 8.8.15 Patch 46, all of which include the necessary fix.

Added: Jul 30, 2025, 3:55 PM
Updated: Jul 30, 2025, 3:55 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
5.0
exploitability
6.9
remediation
7.7
relevance
0.3
threat
1.6
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.