Synacor has released Zimbra version 10.1.19 to patch a critical stored cross-site scripting vulnerability in the Classic Web Client that could allow attackers to execute malicious scripts on devices.
Key Points
- The update addresses a stored cross-site scripting (XSS) flaw that triggers when a user opens a malformed email message.
- Exploitation of this vulnerability could compromise sensitive account settings, mailbox information, and user session data.
- Zimbra advises all customers utilizing the Classic Web Client to install the latest software version immediately.
- While the company currently rates the deployment risk as low, the flaw remains a significant security concern for enterprise users.
- This update follows a history of similar XSS-based security incidents targeting the Zimbra platform throughout 2023 and 2025.