Zimbra Urges Customers to Patch Classic Web Client for Critical XSS Vulnerability
Patch Zimbra Classic Web Client immediately to mitigate XSS that could lead to arbitrary code execution.
Patch Zimbra Classic Web Client immediately to mitigate XSS that could lead to arbitrary code execution.
Summary
Zimbra has identified a critical stored cross‑site scripting (XSS) flaw in its Classic Web Client that could allow specially crafted emails to execute malicious scripts within a user’s session, potentially leading to arbitrary code execution. The vulnerability, which has not yet received a CVE identifier, is actively being exploited in the wild. Zimbra is urging all customers to apply the latest security update immediately to mitigate the risk. The flaw resides in the email rendering engine of the Classic Web Client and can be triggered by maliciously crafted messages. The patch addresses the XSS vector by sanitizing input before rendering. Failure to update could expose users to remote code execution. The advisory emphasizes the urgency of applying the fix before attackers leverage the vulnerability. The update is available through the Zimbra admin console and can be deployed across all affected installations.
Key changes
- Stored XSS in Classic Web Client allows malicious scripts via crafted emails
- Could lead to arbitrary code execution in user sessions
- No CVE assigned yet, but actively exploited
- Zimbra urges customers to apply the latest security update
- Patch sanitizes input before rendering to block the XSS vector