CVE-2025-48700
BaseFortify
Publication date: 2025-06-23
Last updated on: 2026-04-21
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| synacor | zimbra_collaboration_suite | From 10.0.0 (inc) to 10.0.12 (exc) |
| synacor | zimbra_collaboration_suite | From 10.1.0 (inc) to 10.1.4 (exc) |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 8.8.15 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
| synacor | zimbra_collaboration_suite | 9.0.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized access to sensitive information by allowing attackers to run malicious scripts in the context of the user's session. This could result in data theft, session hijacking, or other malicious actions performed on behalf of the user without their consent.
Can you explain this vulnerability to me?
This vulnerability is a Cross-Site Scripting (XSS) issue in the Zimbra Classic UI that allows attackers to execute arbitrary JavaScript within a user's session. It occurs because the application does not properly sanitize HTML content, especially crafted tag structures and attribute values containing an @import directive and other script injection methods. The vulnerability is triggered when a user views a specially crafted email message, without needing any further interaction.