Zimbra patches critical XSS enabling zero-click code execution

Zimbra released a patch for a stored XSS in its Classic Web Client that can allow zero-click code execution when a crafted email is opened. Fix is in v10.1.19 released July 7.

Zimbra released a security update on July 7 to fix a stored cross-site scripting (XSS) flaw in the Classic Web Client that can trigger code execution when a specially crafted email is opened. The fix is included in Zimbra Collaboration version 10.1.19.

The company’s advisory states, “The update fixes a security issue in the Classic Web Client where a specially crafted email could run malicious code when the email is opened. If exploited, it could allow access to mailbox information, session data, or account settings.” Zimbra did not publish technical details of the vulnerability in the advisory.

Google’s Threat Analysis Group (TAG) reported the defect to Zimbra. The issue has not been assigned a public CVE identifier at the time of the advisory. Because the bug is a stored XSS in the web client, rendering the message in the Classic UI can be sufficient to trigger the payload without clicking additional links.

Zimbra urged customers still using the Classic Web Client to install v10.1.19 as soon as possible to receive the security fix, bug repairs and other updates. Organizations that cannot upgrade immediately are advised to apply any available mitigations. Customers upgrading from ZCS 10.0.x, 9.0.x or 8.8.15 should update the SNMP mitigation and reapply it after completing the upgrade, Zimbra noted.

Defenders must rely on the vendor patch and configuration guidance until technical details or exploit reports are published. Organizations that host mailboxes accessible via the Classic Web Client are advised to review logs and session activity for suspicious access around the time of the patch release.

Zimbra, formerly Zimbra Collaboration Suite, provides an integrated email server and web client with messaging, file sharing, calendar and task management. The Classic Web Client remains in use in many deployments that have not migrated to newer interfaces. A public patch is now available; security teams can use the update and Zimbra’s guidance to reduce immediate risk while monitoring for any reports of in-the-wild exploitation.

Articles by this author