CVE-2025-48700
9.5 CISA KEVSynacor · Zimbra Collaboration Suite (ZCS)
A stored Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows unauthenticated attackers to execute arbitrary JavaScript by sending a crafted email.
Executive summary
This critical vulnerability in Zimbra Collaboration Suite (ZCS) is currently being actively exploited in the wild, posing an immediate risk of unauthorized session access and data theft.
Vulnerability
This is a stored XSS vulnerability within the Zimbra Classic UI caused by insufficient sanitization of HTML content in email messages. An unauthenticated attacker can trigger the execution of arbitrary JavaScript simply by sending a malicious email, which executes automatically when viewed by a victim.
Business impact
Successful exploitation allows attackers to gain unauthorized access to sensitive information, including session tokens, account settings, and private mailbox content. Given the CVSS score of 9.5 and the confirmed active exploitation by threat actors, the business impact is severe, potentially resulting in full compromise of user accounts and widespread data exfiltration. Over 10,000 instances remain exposed, significantly increasing the probability of targeted organizational impact.
Remediation
Immediate Action: Administrators must immediately apply the vendor-provided patches: upgrade to 8.8.15 Patch 47, 9.0.0 Patch 43, 10.0.12, or 10.1.4.
Proactive Monitoring: Security teams should monitor mail server logs for suspicious email traffic containing unusual HTML tag structures, specifically those utilizing @import directives or obfuscated script injection patterns.
Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets to filter malicious incoming email content and block requests containing known XSS payloads targeting the Zimbra Classic UI.
Exploitation status
Public Exploit Available: Yes, this vulnerability is confirmed to be actively exploited in the wild.
Analyst recommendation
The severity of this vulnerability, combined with confirmed active exploitation in the wild, necessitates an immediate emergency patching cycle. Organizations running affected versions of Zimbra Collaboration Suite must prioritize the deployment of the specified patches to prevent unauthorized access and potential data exfiltration. If patching is not immediately feasible, consider temporarily disabling the Classic UI or restricting external access to the mail interface until remediation is complete.