Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Evidence dossier
CVE-2024-27443
CVE-2024-27443
gen-56ccdaf9Normalized restatement
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.
- State
- PUBLISHED
- Published
- Aug 12, 2024
- Updated
- Oct 21, 2025
- Evidence coverage
- 85%
2026-07-18 · v2026.06.15 · percentile 97.1%
Distinct CVSS assessments remain side by side; none are averaged.
Source comparison
Who said what
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Probability 0.195430000000; percentile 0.970760000000
Applicability
Cited product scope
[{"status": "affected", "version": "n/a"}]unknowncpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:*; start including 10.0.0; end excluding 10.0.7supportedcpe:2.3:a:zimbra:collaboration:9.0.0:-:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p0:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p1:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p10:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p11:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p12:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p13:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p14:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p15:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p16:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p19:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p2:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p20:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p21:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p23:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p24:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p24.1:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p25:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p26:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p27:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p3:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p30:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p31:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p32:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p33:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p34:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p35:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p36:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p37:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p38:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p4:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p5:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p6:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p7:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p7.1:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p8:*:*:*:*:*:*supportedcpe:2.3:a:zimbra:collaboration:9.0.0:p9:*:*:*:*:*:*supportedAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NLimitations and unknowns
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
- NVD-carried upstream facts remain derivative and are not independent corroboration.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Factor D is unknown in Public Core because no accepted canonical mapping-obligation ledger is present.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.