🟒 CVE-2023-34192

Cross-site scripting vulnerability in Zimbra Collaboration Suite 8.8.15 affecting the /h/autoSaveDraft function. Despite being in CISA KEV, this is an XSS vulnerability that compromises user sessions rather than the server itself, requiring authenticated user interaction for exploitation.

← Back to Overview
LOW_RISK
Risk Level
9.0
CVSS Score
NETWORK
Attack Vector
Execution
ATT&CK Tactic
T1203 β€” Exploitation for Client Execution
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

πŸ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: USER_INTERACTION

CVE Published: 2023-07-06

Added to CISA KEV: 2025-02-25 600 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

πŸ” Web Intelligence (Kagi Β· 2026-06-04)

CVE-2023-34192 is a critical Cross-Site Scripting (XSS) vulnerability affecting Zimbra Collaboration Suite (ZCS) version 8.8.15 [1] [4].

Vulnerability Overview
  • Vulnerability Type: Cross-Site Scripting (XSS) [1].
  • Affected Product: Zimbra Collaboration Suite (ZCS) version 8.8.15 [1].
  • CVSS Score: 9.0 (Critical) [3].
Exploitation and Impact
  • Attack Method: The vulnerability allows a remote, authenticated attacker to inject malicious scripts into the application, specifically via the `/h/autoSaveDraft` function [1] [3].
  • Exploitation Requirements: It requires the attacker to be authenticated [1].
  • Impact: Successful exploitation allows the execution of arbitrary script code in the victim's browser [2]. While some sources note it can potentially lead to arbitrary code execution, this is typically a consequence of the XSS context rather than a direct remote code execution vulnerability [1] [3].
Exploitation Status and Availability
  • Active Exploitation: There is no widely publicized information confirming active exploitation in the wild by specific threat actors or its use in ransomware campaigns.
  • Proof-of-Concept (PoC): Detection templates, such as those from the Nuclei project, are available to identify vulnerable instances [2].
Mitigation
  • Status: Users of Zimbra Collaboration Suite 8.8.15 should consult official Zimbra security advisories for the specific patch or update that addresses this vulnerability. Organizations should prioritize patching given the high CVSS score.

Sources

  1. CVE-2023-34192 Detail - NVD

    Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script. ... Secure .gov websites use HTTPS A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, s…

  2. CVE-2023-34192.yaml - nuclei-templates - GitHub

    Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the victim's browser, leading to ...

  3. PostgreSQL & Zimbra: Vendor Risk Deep Dive

    CVE-2023-34192 is a critical Cross-Site Scripting (XSS) vulnerability affecting Zimbra Collaboration Suite (ZCS) version 8.8.15. This flaw allows remote, authenticated attackers to inject malicious scripts via the /h/autoSaveDraft function, potentially leading to arbitrary code execution. The vulner…

  4. CVE-2023-34192: Zimbra Collaboration Suite XSS Vulnerability

    CVE-2023-34192 is a cross-site scripting vulnerability in Zimbra Collaboration Suite. Learn about its impact, affected versions, and mitigation methods. ... CVE-2023-34192 is a critical Cross-Site Scripting (XSS) vulnerability affecting Zimbra Collaboration Suite (ZCS) version 8.8.15. This ...