S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Nov 25, 2025

CVE-2025-27915 Scanner

CVE-2025-27915 Scanner - Cross-Site Scripting (XSS) vulnerability in Zimbra Collaboration Suite

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
5
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2025-27915
5.4
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient · user interaction needed.

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a <details> tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim's account, including e-mail redirection and data exfiltration.

Attack Vector
Network
Privileges Req.
Low
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Sep 9, 2026View on NVD →
Detail

Zimbra Collaboration Suite is widely used by organizations to streamline their communication processes, involving emails, calendars, and task management functionalities. Various sectors like education, healthcare, and enterprises utilize it for its integrated collaboration features that include email, calendaring, and file sharing within an easily accessed web interface. With its broad deployment in both public and private sectors, Zimbra serves a critical role in maintaining efficient workplace communications. The classic web client, which is commonly used, provides an intuitive interface to access email and calendar functions. Due to its popularity, maintaining secure operation is imperative to prevent unauthorized access to sensitive information. Zimbra continues to be a popular choice for organizations seeking unified communications tools.

The vulnerability detected allows an attacker to exploit Cross-Site Scripting (XSS) within Zimbra Collaboration Suite. By exploiting insufficient HTML content sanitization in ICS files, attackers can insert arbitrary JavaScript code. When a user opens a specially crafted email containing this malicious ICS entry, the JavaScript is executed, leading to potential unauthorized actions. This stored XSS vulnerability is particularly concerning as it can be leveraged for email redirection and data exfiltration. It affects specific versions of Zimbra, making it crucial for system administrators to check their installations. As this vulnerability exists in the web client, any abuse can affect the continuity of secure communications.

Technically, the XSS vulnerability stems from improper sanitization of HTML content within ICS files in the Classic Web Client. Upon viewing an email with a malicious ICS entry, JavaScript code embedded through an ontoggle event within a details tag executes. This enables attackers to potentially perform unauthorized actions, including redirecting email or exfiltrating sensitive information. Critical endpoints such as those handling email view functionalities in affected versions are most susceptible. The flaw poses significant security concerns, particularly for installations that have not undergone recent security updates. Ensuring ICS file processing is secure is key to preventing such exploitation within the platform.

The exploitation of this vulnerability could lead to severe consequences for affected users and organizations. If a malicious ICS file is opened, attackers can execute unauthorized JavaScript, harming the confidentiality and integrity of user communications. Such scenarios can result in unauthorized email access or redirection, compromising private information. Furthermore, sensitive data collected through these attacks can be exfiltrated and misused, leading to significant privacy breaches. This vulnerability can also decrease user trust in the platform, impacting its reputation and reliability. Organizations might face regulatory consequences if customer data is inadvertently exposed or stolen.

REFERENCES

Solution Advice
  • Update to the latest version of Zimbra Collaboration Suite that addresses this vulnerability.
  • Apply security patches provided by Zimbra for the affected versions.
  • Restrict access to the affected web client to only authorized users.
  • Educate users on the risks of opening emails from untrusted sources, especially those containing ICS files.
  • Implement web application firewalls to detect and block malicious ICS files attempting to exploit this flaw.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-27915 Scanner - Cross-Site Scripting (XSS) vulnerability in Zimbra Collaboration Suite | S4E