Cross-site scripting in Zimbra Collaboration - #VU144521
Published: August 21, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in the victim's browser.
The vulnerability exists due to stored cross-site scripting in the Classic Web Client field handling when processing crafted fields. A remote user can store crafted fields to execute arbitrary script in the victim's browser.
The malicious content executes under specific conditions.