Zimbra Collaboration Suite Reflected Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Zimbra Collaboration Suite (ZCS) versions 10.0 and 10.1. This vulnerability exists within the Classic Webmail REST interface (/h/rest), where the application fails to adequately sanitize user input. This flaw allows an unauthenticated attacker to inject malicious JavaScript into a crafted URL. When a victim accesses this link, the injected script executes within the context of the Zimbra webmail application, potentially enabling the attacker to perform actions on behalf of the victim.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject and execute malicious scripts in the context of the user's session.

Remediation

Users can upgrade to ZCS version 10.1.16 or 10.0.12, both of which include the necessary patch. Instructions for upgrading can be found on the Zimbra website.

Added: Mar 20, 2026, 2:24 PM
Updated: Mar 20, 2026, 2:24 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.7
exploitability
6.4
remediation
7.7
relevance
4.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.