Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2023-37580
CVE
CVE-2023-37580
View on NVD ↗
Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
MITRE ATT&CK TTPs
1
T1059.001
PowerShell
Execution
Source Articles
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
A critical stored cross-site scripting (XSS) vulnerability in Zimbra's Classic Web Client could allow attackers to execute malicious scripts in user sessions via specially crafted emails. If exploited, the flaw could enable access to mailbox data, session information, and account settings. While Zimbra has not confirmed active exploitation, similar XSS flaws in Zimbra have been historically targeted. Users are advised to update to Zimbra Collaboration Suite version 10.1.19 for protection.
hacker-news
Jul 11, 2026