February 25, 2022 · Applied Cybernetics Group
CVE-2022-24682 — Synacor Zimbra Collaborate Suite (ZCS)
known ransomware use
Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability
- Added to KEV
2022-02-25- Federal due date
2022-03-11- Vendor
- Synacor
- Product
- Zimbra Collaborate Suite (ZCS)
- EPSS
- 98.2th percentile (score 0.309, as of
2026-09-16) - NVD CVSS v3.1
- 6.1 (MEDIUM)
- Ransomware use
- Known
- ATT&CK
- T1059.007 , T1185 , T1204.001 · signal rollup
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2022-24682
CISA short description
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code.
Required action
Apply updates per vendor instructions.
NVD description
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.