Cross-site scripting in Zimbra Collaboration - #VU144520
Published: August 21, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in the victim's browser.
The vulnerability exists due to stored cross-site scripting in the Classic Web Client attachment filename handling when rendering malicious attachment filenames. A remote user can store a crafted attachment filename to execute arbitrary script in the victim's browser.
User interaction is required to render the malicious content under specific conditions.