CVE-2022-24682
Summary
| CVE | CVE-2022-24682 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-09 04:15:00 UTC |
| Updated | 2023-08-08 14:21:00 UTC |
| Description | An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document. |
Risk And Classification
EPSS: 0.879680000 probability, percentile 0.994750000 (date 2026-04-01)
CISA KEV: Listed on 2022-02-25; due 2022-03-11; ransomware use Known
Problem Types: CWE-116
CISA Known Exploited Vulnerability
| Vendor | Synacor |
|---|---|
| Product | Zimbra Collaborate Suite (ZCS) |
| Name | Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2022-24682 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Zimbra | Collaboration | All | All | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | - | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p1 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p10 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p11 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p12 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p13 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p14 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p15 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p16 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p17 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p18 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p19 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p2 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p20 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p21 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p22 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p23 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p24 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p25 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p26 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p27 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p28 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p29 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p3 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p4 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p5 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p6 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p7 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p8 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p9 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Operation EmailThief: Active Exploitation of Zero-day XSS Vulnerability in Zimbra | Volexity | MISC | www.volexity.com | |
| Hotfix Available 5 Feb for Zero-day Exploit Vulnerability in Zimbra 8.8.15 - Zimbra : Blog | MISC | blog.zimbra.com | |
| wiki.zimbra.com/wiki/Zimbra_Security_Advisories | MISC | wiki.zimbra.com | |
| wiki.zimbra.com/wiki/Security_Center | MISC | wiki.zimbra.com | |
| Zimbra Releases/8.8.15/P30 - Zimbra :: Tech Center | MISC | wiki.zimbra.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 376478 Zimbra Cross-Site Scripting (XSS) Vulnerability