CVE-2026-33370 describes a stored Cross-Site Scripting (XSS) vulnerability in Zimbra Collaboration (ZCS) versions 10.0 and 10.1, specifically within the Briefcase feature. This flaw allows an attacker to embed malicious scripts in uploaded, publicly shared files due to insufficient sanitization. When a user opens such a file, the embedded script executes in their session, potentially leading to data exfiltration or unauthorized actions. Rated with a CVSS score of 6.1 (Medium), exploitation requires user interaction but has low attack complexity and can be performed remotely. There is currently no evidence of active exploitation, public exploit code, or significant community attention for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.0, < 10.1.16CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.