Cross-site scripting in Zimbra Collaboration - #VU144520

 

Cross-site scripting in Zimbra Collaboration - #VU144520

Published: August 21, 2026


Vulnerability identifier: #VU144520
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in the victim's browser.

The vulnerability exists due to stored cross-site scripting in the Classic Web Client attachment filename handling when rendering malicious attachment filenames. A remote user can store a crafted attachment filename to execute arbitrary script in the victim's browser.

User interaction is required to render the malicious content under specific conditions.


Affected software

Zimbra Collaboration

Remediation

Install security update from vendor's website.

Zimbra Collaboration - update to 10.1.20

External References

Related Security Bulletins