CVE-2022-24682 is a cross-site scripting (XSS) vulnerability in the Calendar feature of Zimbra Collaboration Suite versions 8.8.x before 8.8.15 patch 30 (update 1). An attacker can inject arbitrary HTML containing executable JavaScript into element attributes, which then becomes unescaped in the document. This medium-severity vulnerability (CVSS 6.1) has a high EPSS score and FAUCET Risk Score of 100/100, indicating significant exploitability and impact, including potential information disclosure and integrity compromise. It is actively exploited in the wild, with evidence of use in ransomware campaigns, and has garnered substantial community discussion and media coverage, including warnings from CISA. While no Metasploit or ExploitDB modules exist, Nuclei templates are available for detection.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.8.0, < 8.8.15CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:* | ||
8.8.15CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:-:*:*:*:*:*:* | ||
8.8.15CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p1:*:*:*:*:*:* | ||
8.8.15CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p10:*:*:*:*:*:* | ||
8.8.15CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p11:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.