vulnerability

Zimbra Collaboration: CVE-2024-45515: Resolved Cross-Site Scripting (XSS) vulnerability.

Severity
6
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:N)
Published
Jul 30, 2025
Added
Jul 30, 2025
Modified
Aug 27, 2025

Description

An issue was discovered in zimbra collaboration (zcs) through 10.1. a cross-site scripting (xss) vulnerability exists in zimbra webmail due to insufficient validation of the content type metadata when importing files into the briefcase. attackers can exploit this issue by crafting a file with manipulated metadata, allowing them to bypass content type checks and execute arbitrary javascript within the victim's session.

Solution

zimbra-collaboration-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.