Zimbra Patches Critical Code Execution Vulnerability
A critical cross-site scripting (XSS) vulnerability in Zimbra’s Classic Web Client could allow attackers to execute code on a victim’s system simply by opening a specially crafted email. Zimbra has released version 10.1.19 to address this issue, and users are urged to update immediately to prevent exploitation. The vulnerability was initially reported by Google Threat Analysis Group (GTIG).
A critical security vulnerability exists within Zimbra, a popular collaboration solution offering email, messaging, and file sharing capabilities. The vulnerability, a stored cross-site scripting (XSS) flaw, resides within the Classic Web Client and allows for zero-click code execution when a user opens a malicious email. Zimbra announced the patch on July 7th, releasing version 10.1.19 to resolve the issue. The vulnerability was discovered by Google Threat Analysis Group (GTIG), a group often targeting security defects exploited by state-sponsored groups and commercial spyware vendors. To mitigate the risk, Zimbra recommends that all users upgrading from ZCS versions 10.0.x, 9.0.x, or 8.8.15 apply the SNMP mitigation patch after upgrading to version 10.1.19. This ensures that any previously applied SNMP mitigations are correctly re-applied following the upgrade.