Cross-site scripting in Zimbra Collaboration - #VU144521

 

Cross-site scripting in Zimbra Collaboration - #VU144521

Published: August 21, 2026


Vulnerability identifier: #VU144521
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in the victim's browser.

The vulnerability exists due to stored cross-site scripting in the Classic Web Client field handling when processing crafted fields. A remote user can store crafted fields to execute arbitrary script in the victim's browser.

The malicious content executes under specific conditions.


Affected software

Zimbra Collaboration

Remediation

Install security update from vendor's website.

Zimbra Collaboration - update to 10.1.20

External References

Related Security Bulletins