CVE-2023-34192

Published Jul 6, 2023

Last updated a month ago

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2023-34192 is a cross-site scripting (XSS) vulnerability found in Synacor Zimbra Collaboration Suite (ZCS). It allows a remote, authenticated attacker to execute arbitrary code by sending a specially crafted script to the `/h/autoSaveDraft` function. This vulnerability affects ZCS version 8.8.15. The vulnerability was patched in July 2023 with the release of version 8.8.15 Patch 40. The fix involves sanitizing user input to prevent malicious script execution. Administrators were also provided with instructions to manually patch the vulnerability by editing a specific data file. While there are no public reports of exploitation as of today (February 26, 2025), CISA has added this vulnerability to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Federal Civilian Executive Branch agencies are required to patch this vulnerability by March 18, 2025.

Description
Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.
Source
cve@mitre.org
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9
Impact score
6
Exploitability score
2.3
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Exploit added on
Feb 25, 2025
Exploit action due
Mar 18, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
CWE-79
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-79

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1

  1. CISA (U.S. Cybersecurity Agency) has warned that two dangerous vulnerabilities are being actively used in attacks: 1. Microsoft Partner Center flaw (CVE-2024-49035) 2. Synacor Zimbra Collaboration Suite flaw (CVE-2023-34192) 📖 Full details here: (https://t.co/fsiCPwS00I…)

    @nathy_hackers

    1 Apr 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CISA (U.S. Cybersecurity Agency) has warned that two dangerous vulnerabilities are being actively used in attacks: 1. Microsoft Partner Center flaw (CVE-2024-49035) 2. Synacor Zimbra Collaboration Suite flaw (CVE-2023-34192) 📖 Full details here: (https://t.co/Uld9sf1RzZ…)

    @John08987

    31 Mar 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CISA (U.S. Cybersecurity Agency) has warned that two dangerous vulnerabilities are being actively used in attacks: 1. Microsoft Partner Center flaw (CVE-2024-49035) 2. Synacor Zimbra Collaboration Suite flaw (CVE-2023-34192) 📖 Full details here: (https://t.co/eL6mIN6wAi…)

    @digital_hack6

    27 Mar 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CISA (U.S. Cybersecurity Agency) has warned that two dangerous vulnerabilities are being actively used in attacks: 1. Microsoft Partner Center flaw (CVE-2024-49035) 2. Synacor Zimbra Collaboration Suite flaw (CVE-2023-34192) 📖 Full details here: (https://t.co/UFdvAPacWg…)

    @recoverythreata

    27 Mar 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CISA (U.S. Cybersecurity Agency) has warned that two dangerous vulnerabilities are being actively used in attacks: 1. Microsoft Partner Center flaw (CVE-2024-49035) 2. Synacor Zimbra Collaboration Suite flaw (CVE-2023-34192) 📖 Full details here: (https://t.co/28uWAZuGes…)

    @EthicalHack21

    23 Mar 2025

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CISA (U.S. Cybersecurity Agency) has warned that two dangerous vulnerabilities are being actively used in attacks: 1. Microsoft Partner Center flaw (CVE-2024-49035) 2. Synacor Zimbra Collaboration Suite flaw (CVE-2023-34192) 📖 Full details here: (https://t.co/zzUxb93uRV…)

    @Cyber_Recover12

    22 Mar 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CISA (U.S. Cybersecurity Agency) has warned that two dangerous vulnerabilities are being actively used in attacks: 1. Microsoft Partner Center flaw (CVE-2024-49035) 2. Synacor Zimbra Collaboration Suite flaw (CVE-2023-34192) 📖 Full details here: (https://t.co/zzUxb93uRV…)

    @Cyber_Recover12

    21 Mar 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CISA (U.S. Cybersecurity Agency) has warned that two dangerous vulnerabilities are being actively used in attacks: 1. Microsoft Partner Center flaw (CVE-2024-49035) 2. Synacor Zimbra Collaboration Suite flaw (CVE-2023-34192) 📖 Full details here: (https://t.co/NIu1skgdgd…)

    @JOE_HACKER1

    20 Mar 2025

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CISA (U.S. Cybersecurity Agency) has warned that two dangerous vulnerabilities are being actively used in attacks: 1. Microsoft Partner Center flaw (CVE-2024-49035) 2. Synacor Zimbra Collaboration Suite flaw (CVE-2023-34192) 📖 Full details here: (https://t.co/aTTn63279U…)

    @Mr_James_Cyber

    20 Mar 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CISA (U.S. Cybersecurity Agency) has warned that two dangerous vulnerabilities are being actively used in attacks: 1. Microsoft Partner Center flaw (CVE-2024-49035) 2. Synacor Zimbra Collaboration Suite flaw (CVE-2023-34192) 📖 Full details here: (https://t.co/aTTn63279U…)

    @Mr_James_Cyber

    20 Mar 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CISA (U.S. Cybersecurity Agency) has warned that two dangerous vulnerabilities are being actively used in attacks: 1. Microsoft Partner Center flaw (CVE-2024-49035) 2. Synacor Zimbra Collaboration Suite flaw (CVE-2023-34192) 📖 Full details here: (https://t.co/5EhdO34zav…)

    @Recoverytheate

    20 Mar 2025

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CISA (U.S. Cybersecurity Agency) has warned that two dangerous vulnerabilities are being actively used in attacks: 1. Microsoft Partner Center flaw (CVE-2024-49035) 2. Synacor Zimbra Collaboration Suite flaw (CVE-2023-34192) 📖 Full details here: (https://t.co/NIu1skgdgd…)

    @JOE_HACKER1

    20 Mar 2025

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. CISA (U.S. Cybersecurity Agency) has warned that two dangerous vulnerabilities are being actively used in attacks: 1. Microsoft Partner Center flaw (CVE-2024-49035) 2. Synacor Zimbra Collaboration Suite flaw (CVE-2023-34192) 📖 Full details here: (https://t.co/fU7P8x4DGz…)

    @Herbert_Termux

    19 Mar 2025

    98 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. CISA (U.S. Cybersecurity Agency) has warned that two dangerous vulnerabilities are being actively used in attacks: 1. Microsoft Partner Center flaw (CVE-2024-49035) 2. Synacor Zimbra Collaboration Suite flaw (CVE-2023-34192) 📖 Full details here: (https://t.co/EWaMDc2cR9…)

    @help_center11

    11 Mar 2025

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. CISA (U.S. Cybersecurity Agency) has warned that two dangerous vulnerabilities are being actively used in attacks: 1. Microsoft Partner Center flaw (CVE-2024-49035) 2. Synacor Zimbra Collaboration Suite flaw (CVE-2023-34192) 📖 Full details here: (https://t.co/JVRhmHVpR1…)

    @savana_recovery

    10 Mar 2025

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Actively exploited CVE : CVE-2024-49035, CVE-2023-34192

    @transilienceai

    9 Mar 2025

    73 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  17. 🔎 VulnWatch Friday: CVE-2023-34192 🔓 @CISAgov has added a critical @Zimbra XSS vulnerability allowing remote code execution via crafted script to its KEV catalog. 🔧 Fix: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services. htt

    @kpoireault

    7 Mar 2025

    77 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Actively exploited CVE : CVE-2024-49035, CVE-2023-34192

    @transilienceai

    28 Feb 2025

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  19. Actively exploited CVE : CVE-2024-49035, CVE-2023-34192

    @transilienceai

    28 Feb 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  20. CISA (U.S. Cybersecurity Agency) has warned that two dangerous vulnerabilities are being actively used in attacks: 1. Microsoft Partner Center flaw (CVE-2024-49035) 2. Synacor Zimbra Collaboration Suite flaw (CVE-2023-34192) 📖 Full details here: (https://t.co/6jycjWiyri…)

    @AdrianT_ech

    27 Feb 2025

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2023-34192 #Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability https://t.co/PRQR26SrLx

    @ScyScan

    26 Feb 2025

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 🔐 CISA has just added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog—both actively exploited. Hook: Microsoft Partner Center’s CVE-2024-49035 and Synacor ZCS’s CVE-2023-34192 are putting organizations at risk. Read the full article:… https://

    @TheHackersNews

    26 Feb 2025

    34078 Impressions

    31 Retweets

    89 Likes

    11 Bookmarks

    1 Reply

    0 Quotes

Configurations