TROYANOSYVIRUS
Retour aux CVEs

CVE-2025-66376

HIGHCISA KEV
7.2

Description

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

Details CVE

Score CVSS v3.17.2
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie1/5/2026
Derniere modification3/18/2026
Sourcekev
Observations honeypot0

CISA KEV

FournisseurSynacor
ProduitZimbra Collaboration Suite (ZCS)
Nom vulnerabiliteSynacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
Date ajout KEV2026-03-18
Date limite remediation2026-04-01
Utilise dans ransomwareUnknown

Produits affectes

synacor:zimbra_collaboration_suite

Faiblesses (CWE)

CWE-79

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.