← Back to browse · API

CVE-2024-27443

Severity
MEDIUM
CVSS
6.1
EPSS
0.23632
Risk score
57.67
CISA KEV
Yes
PoC
No
Published
2025-05-19
Modified
2025-05-19
First seen
2026-08-07
Aliases
EUVD-2024-24646, GHSA-QRVG-MG33-Q843
Products
Synacor:Zimbra Collaboration Suite (ZCS), n/a:n/a n/a
Sources
cisa.gov CVE-2024-27443
euvd EUVD-2024-24646

Description

Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra webmail classic user interface. An attacker can exploit this vulnerability via an email message containing a crafted calendar header, leading to the execution of arbitrary JavaScript code.

References