Attacker Value
Very High
(1 user assessed)
Exploitability
Unknown
(1 user assessed)
User Interaction
Required
Privileges Required
None
Attack Vector
Network
2

CVE-2023-37580

Disclosure Date: July 31, 2023
Exploited in the Wild
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.

Add Assessment

1
Ratings
  • Attacker Value
    Very High
Technical Analysis

Per Google’s Threat Analysis Group (TAG), this bug was exploited as a zero-day and has been used by at least four different threat actors to “steal email data, user credentials, and authentication tokens.” Threat campaigns have targeted Greece, Moldova, Tunisia, Vietnam, and Pakistan.

CVSS V3 Severity and Metrics
Base Score:
6.1 Medium
Impact Score:
2.7
Exploitability Score:
2.8
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
Required
Scope (S):
Changed
Confidentiality (C):
Low
Integrity (I):
Low
Availability (A):
None

General Information

Vendors

  • zimbra

Products

  • zimbra,
  • zimbra 8.8.15

Exploited in the Wild

Reported by:

Additional Info

Technical Analysis