{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2024-27443/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2024-27443/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2024-27443/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2024-27443/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2024-27443/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2024-27443"},"sightings":{"href":"/api/v1/sightings/cve-2024-27443"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2024/CVE-2024-27443.yaml","nuclei_template_severity":"medium","nuclei_template_yaml":"id: CVE-2024-27443\n\ninfo:\n  name: Zimbra Collaboration - Cross-Site Scripting (XSS)\n  author: rxerium\n  severity: medium\n  description: |\n    An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload.\n  impact: |\n    Unauthenticated attackers can execute arbitrary JavaScript via crafted calendar headers in emails, potentially stealing user credentials or session data.\n  remediation: |\n    Update Zimbra Collaboration to version 9.0.0 P39 or 10.0.7 or later.\n  reference:\n    - https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.7#Security_Fixes\n    - https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P39#Security_Fixes\n    - https://nvd.nist.gov/vuln/detail/CVE-2024-27443\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N\n    cvss-score: 6.1\n    cve-id: CVE-2024-27443\n    cwe-id: CWE-79\n    epss-score: 0.23632\n    epss-percentile: 0.97707\n    cpe: cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: zimbra\n    product: collaboration\n    shodan-query:\n      - http.favicon.hash:\"1624375939\"\n      - http.html:\"zimbra collaboration suite web client\"\n      - http.favicon.hash:\"475145467\"\n    fofa-query:\n      - icon_hash=\"1624375939\"\n      - app=\"zimbra-邮件系统\"\n      - body=\"zimbra collaboration suite web client\"\n      - icon_hash=\"475145467\"\n  tags: cve,cve2024,zimbra,kev,passive,xss,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/js/zimbraMail/share/model/ZmSettings.js\"\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - \"Zimbra Collaboration\"\n\n      - type: word\n        part: content_type\n        words:\n          - \"application/x-javascript\"\n\n      - type: dsl\n        dsl:\n          - compare_versions(version, '9.0.0')\n          - compare_versions(version, '>= 10.0.0', '< 10.0.7')\n        condition: or\n\n    extractors:\n      - type: regex\n        part: body\n        name: version\n        group: 1\n        regex:\n          - CLIENT_VERSION\\\",\\s+{type:ZmSetting\\.T_CONFIG, defaultValue:\"([0-9.]+)_([A-Z_0-9]+)\"\\}\n# digest: 4a0a0047304502210092a119394683db5b4a5cf8d4eb339f9343e4826a25d80445bd4caecd6f50a45e022038934eedbfb833916e7fb91d8ed0e54084366c52ee1c2a03a3366b6b8a6729d4:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2024-27443"}