HomeSynacorCVE-2024-45516

CVE-2024-45516

MEDIUM
6.1CVSS
Published: 2025-05-14
Updated: 2025-06-11
AI Analysis

Description

An issue was discovered in Zimbra Collaboration (ZCS) 9.0.0 before Patch 43, 10.0.x before 10.0.12, 10.1.x before 10.1.4, and 8.8.15 before Patch 47. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. This issue arises from insufficient sanitization of HTML content, including malformed <img> tags with embedded JavaScript. The vulnerability is triggered when a user views a specially crafted email in the Classic UI, requiring no additional user interaction.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
network
Complexity
low
Privileges
none
User Action
required
Scope
changed
Confidentiality
low
Integrity
low
Availability
none
Weaknesses
CWE-79

Metadata

Primary Vendor
SYNACOR
Published
5/14/2025
Last Modified
6/11/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

synacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suitesynacor : zimbra_collaboration_suite

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2024-45516 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com