Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to…
| CVE ID | CVE-2025-48700 |
| Vendor | Synacor |
| Affected Product | Zimbra Collaboration Suite (ZCS) |
| Vulnerability Type | Vulnerability |
| CVSS Score | 9.5 (CRITICAL) |
| Actively Exploited | ✅ Yes — CISA KEV Listed |
| Patch Status | See Vendor Advisory → |
| Reported By | CYBERDUDEBIVASH SENTINEL APEX Intelligence (via cisa_kev) |
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information.
Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.