CVE-2024-27443
Unknown Unknown - Not Provided

BaseFortify

Vulnerability report for CVE-2024-27443, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2024-08-12

Last updated on: 2025-10-31

Assigner: MITRE

Description

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2024-08-12
Last Modified
2025-10-31
Generated
2026-09-27
AI Q&A
2025-05-20
EPSS Evaluated
2026-09-25
NVD

Affected Vendors & Products

Showing 38 associated CPEs
Vendor Product Version / Range
zimbra collaboration From 10.0.0 (inc) to 10.0.7 (exc)
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0
zimbra collaboration 9.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2024-27443 is a Cross-Site Scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra webmail classic user interface. It occurs due to improper input validation in handling the calendar header, allowing an attacker to embed malicious JavaScript code in a crafted calendar header within an email. When a victim views this email in the vulnerable Zimbra webmail interface, the malicious script executes in the context of the victim's session, potentially allowing arbitrary JavaScript code execution. ['CVE description']

Impact Analysis

This vulnerability can be exploited by attackers to execute arbitrary JavaScript code in the context of a victim's webmail session. This can lead to credential theft, data exfiltration of emails and contacts, and potentially bypassing security mechanisms such as two-factor authentication. Specifically, it has been exploited in a cyberespionage campaign (Operation RoundPress) targeting high-value webmail servers, enabling attackers to steal confidential data and gain unauthorized access to email accounts. ['CVE description', 3]

Mitigation Strategies

To mitigate CVE-2024-27443, immediately apply the security patches provided in Zimbra Collaboration versions 9.0.0 Patch 39 and 10.0.7, which address this Local Privilege Escalation vulnerability. These patches include updates to relevant components and security hardening measures. Additionally, upgrade the Nginx package to version 1.24.0 as included in these releases. Ensure OpenSSL 3.0 is configured with FIPS compliance enabled by default, enforcing TLS 1.2 as the minimum supported version. If issues arise, follow instructions to enable or disable the FIPS provider. Also, verify that any SAML and SSO-based login configurations have the zimbraVirtualHostName parameter set before upgrading. For environments using OpenJDK 17, consider the impact on Kerberos encryption and configure allow_weak_crypto in krb5.conf if necessary, followed by a mailboxd service restart. These steps collectively help mitigate the vulnerability and improve overall security. [1, 2]

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2024-27443. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart