Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54837 | An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability exists in Zimbra webmail due to insufficient validation of the content type metadata when importing files into the briefcase. Attackers can exploit this issue by crafting a file with manipulated metadata, allowing them to bypass content type checks and execute arbitrary JavaScript within the victim's session. |
Thu, 07 Aug 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zimbra collaboration
|
|
| CPEs | cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zimbra collaboration
|
Thu, 31 Jul 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zimbra
Zimbra zimbra Zimbra zimbra Collaboration Suite |
|
| Vendors & Products |
Zimbra
Zimbra zimbra Zimbra zimbra Collaboration Suite |
Wed, 30 Jul 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Wed, 30 Jul 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability exists in Zimbra webmail due to insufficient validation of the content type metadata when importing files into the briefcase. Attackers can exploit this issue by crafting a file with manipulated metadata, allowing them to bypass content type checks and execute arbitrary JavaScript within the victim's session. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-07-30T18:52:05.267Z
Reserved: 2024-09-01T00:00:00.000Z
Link: CVE-2024-45515
Updated: 2025-07-30T18:51:58.575Z
Status : Analyzed
Published: 2025-07-30T15:15:32.373
Modified: 2025-08-07T18:16:45.977
Link: CVE-2024-45515
No data.
OpenCVE Enrichment
Updated: 2025-07-31T10:09:17Z
EUVD