CVE-2024-45515

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability exists in Zimbra webmail due to insufficient validation of the content type metadata when importing files into the briefcase. Attackers can exploit this issue by crafting a file with manipulated metadata, allowing them to bypass content type checks and execute arbitrary JavaScript within the victim's session.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:*

History

07 Aug 2025, 18:16

Type Values Removed Values Added
References () https://wiki.zimbra.com/wiki/Security_Center - () https://wiki.zimbra.com/wiki/Security_Center - Release Notes
References () https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.9#Security_Fixes - () https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.9#Security_Fixes - Release Notes
References () https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy - () https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy - Product
References () https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories - () https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories - Vendor Advisory
First Time Zimbra
Zimbra collaboration
CPE cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:*

31 Jul 2025, 18:42

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en Zimbra Collaboration (ZCS) hasta la versión 10.1. Existe una vulnerabilidad de cross-site scripting (XSS) en el correo web de Zimbra debido a una validación insuficiente de los metadatos del tipo de contenido al importar archivos al maletín. Los atacantes pueden explotar este problema creando un archivo con metadatos manipulados, lo que les permite eludir las comprobaciones del tipo de contenido y ejecutar JavaScript arbitrario en la sesión de la víctima.

30 Jul 2025, 19:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

30 Jul 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-30 15:15

Updated : 2025-08-07 18:16


NVD link : CVE-2024-45515

Mitre link : CVE-2024-45515

CVE.ORG link : CVE-2024-45515


JSON object : View

Products Affected

zimbra

  • collaboration
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')