CISA Known Exploited Vulnerability

CVE-2022-24682 Ransomware

Synacor · Zimbra Collaborate Suite (ZCS)

Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability

Date added
BOD 22-01 due date
CWE CWE-79, CWE-116
Ransomware Known

CISA description

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code.

Required action

Apply updates per vendor instructions.