Cross-site scripting in Zimbra Collaboration - #VU144522

 

Cross-site scripting in Zimbra Collaboration - #VU144522

Published: August 21, 2026


Vulnerability identifier: #VU144522
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in the victim's browser.

The vulnerability exists due to stored cross-site scripting in the Classic Web Client field rendering when rendering a crafted field. A remote user can store a crafted field to execute arbitrary script in the victim's browser.

User interaction is required to render the malicious content.


Affected software

Zimbra Collaboration

Remediation

Install security update from vendor's website.

Zimbra Collaboration - update to 10.1.20

External References

Related Security Bulletins