#VU118170 Stored cross-site scripting in Zimbra Collaboration
Published: November 6, 2025
Zimbra Collaboration
Synacor Inc.
Description
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in Zimbra Mail Client for emails with PDF attachments. A remote attacker can send a specially crafted email to the victim and execute arbitrary HTML and script code in user's browser in context of vulnerable website.