CVE-2025-27915

MEDIUM KEV NUCLEI

Zimbra - Cross-Site Scripting via ICS Files

Title source: nuclei
STIX 2.1

Exploitation Summary

CVE-2025-27915 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added October 7, 2025. EIP tracks 1 public exploit from researchers including HORKimhab. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository contains a markdown file describing CVE-2025-27915, a stored XSS vulnerability in Zimbra Collaboration (ZCS) 9.0, 10.0, and 10.1. The writeup explains the root cause (insufficient HTML sanitization in ICS files) and attack vector (malicious JavaScript in ontoggle events), but no functional exploit code is provided.

Description

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a <details> tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim's account, including e-mail redirection and data exfiltration.

Exploits (1)

github STUB
by HORKimhab · poc
https://github.com/HORKimhab/poc-cve-collection/tree/main/2025/27xxx/CVE-2025-27915.md

The repository contains a markdown file describing CVE-2025-27915, a stored XSS vulnerability in Zimbra Collaboration (ZCS) 9.0, 10.0, and 10.1. The writeup explains the root cause (insufficient HTML sanitization in ICS files) and attack vector (malicious JavaScript in ontoggle events), but no functional exploit code is provided.

Classification
Stub 95%
Attack Type
Xss
Complexity
Moderate
Reliability
Theoretical
Target: Zimbra Collaboration (ZCS) 9.0, 10.0, 10.1
No auth needed
Prerequisites: Victim must view an email containing a malicious ICS file in the Classic Web Client
mistral-large-3 · analyzed Jul 12, 2026 Full analysis →

Nuclei Templates (1)

Zimbra - Cross-Site Scripting via ICS Files
MEDIUMVERIFIEDby Snbig,EhsanCreator,eliotworkspac-max
Shodan: http.title:"Zimbra Collaboration Suite"
FOFA: title="Zimbra Collaboration Suite"

Scores

CVSS v3 5.4
EPSS 0.0434
EPSS Percentile 90.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2025-10-07
VulnCheck KEV 2025-09-30
ENISA EUVD EUVD-2025-7823
CWE
CWE-79
Status published
Products (2)
synacor/zimbra_collaboration_suite 9.0.0 (45 CPE variants)
synacor/zimbra_collaboration_suite 10.0.0 - 10.0.13
Published Mar 12, 2025
KEV Added Oct 07, 2025
Tracked Since Feb 18, 2026