CISA Known Exploited Vulnerability

CVE-2022-27926

Synacor · Zimbra Collaboration Suite (ZCS)

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Date added
BOD 22-01 due date
CWE CWE-79, CWE-138
Ransomware Unknown

CISA description

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability by allowing an endpoint URL to accept parameters without sanitizing.

Required action

Apply updates per vendor instructions.