AUTO-UPDATED

Zimbra patched a flaw that let hackers hijack accounts just by sending an email

Synacor has released Zimbra version 10.1.19 to patch a critical stored cross-site scripting vulnerability in the Classic Web Client that could allow attackers to execute malicious scripts on devices.

Key Points

  • The update addresses a stored cross-site scripting (XSS) flaw that triggers when a user opens a malformed email message.
  • Exploitation of this vulnerability could compromise sensitive account settings, mailbox information, and user session data.
  • Zimbra advises all customers utilizing the Classic Web Client to install the latest software version immediately.
  • While the company currently rates the deployment risk as low, the flaw remains a significant security concern for enterprise users.
  • This update follows a history of similar XSS-based security incidents targeting the Zimbra platform throughout 2023 and 2025.

Why it Matters

This security patch is essential for protecting enterprise communication infrastructure from persistent XSS threats that have historically targeted Zimbra users. Promptly applying this update prevents potential unauthorized access to sensitive corporate data and mitigates the risk of account compromise.
TechSpot Published by Alfonso Maruccia
Read original