CVE-2022-24682
Summary
| CVE | CVE-2022-24682 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-09 04:15:07 UTC |
| Updated | 2026-08-07 05:16:55 UTC |
| Description | An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document. |
Risk And Classification
Primary CVSS: v3.1 6.1 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS: 0.309310000 probability, percentile 0.980900000 (date 2026-08-12)
CISA KEV: Listed on 2022-02-25; due 2022-03-11; ransomware use Known
Problem Types: CWE-116 | n/a | CWE-116 CWE-116 Improper Encoding or Escaping of Output
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 6.1 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| 3.1 | ADP | DECLARED | 6.1 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 6.1 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| 2.0 | [email protected] | Primary | 4.3 | AV:N/AC:M/Au:N/C:N/I:P/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
CISA Known Exploited Vulnerability
| Vendor | Synacor |
|---|---|
| Product | Zimbra Collaborate Suite (ZCS) |
| Name | Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2022-24682 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Synacor | Zimbra Collaboration Suite | All | All | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | - | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p1 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p10 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p11 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p12 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p13 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p14 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p15 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p16 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p17 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p18 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p19 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p2 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p20 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p21 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p22 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p23 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p24 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p25 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p26 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p27 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p28 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p29 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p3 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p4 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p5 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p6 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p7 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p8 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p9 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| Operation EmailThief: Active Exploitation of Zero-day XSS Vulnerability in Zimbra | Volexity | af854a3a-2127-422b-91ae-364da2661108 | www.volexity.com | Exploit, Third Party Advisory |
| Hotfix Available 5 Feb for Zero-day Exploit Vulnerability in Zimbra 8.8.15 - Zimbra : Blog | af854a3a-2127-422b-91ae-364da2661108 | blog.zimbra.com | Vendor Advisory |
| Zimbra Releases/8.8.15/P30 - Zimbra :: Tech Center | af854a3a-2127-422b-91ae-364da2661108 | wiki.zimbra.com | Release Notes, Vendor Advisory |
| wiki.zimbra.com/wiki/Security_Center | af854a3a-2127-422b-91ae-364da2661108 | wiki.zimbra.com | Vendor Advisory |
| wiki.zimbra.com/wiki/Zimbra_Security_Advisories | af854a3a-2127-422b-91ae-364da2661108 | wiki.zimbra.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 376478 Zimbra Cross-Site Scripting (XSS) Vulnerability