HomeVulnerabilitiesCVE-2025-48700
Active Exploitation

CVE-2025-48700

Share this vulnerability:

Description

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. This issue arises from insufficient sanitization of HTML content, specifically involving crafted tag structures and attribute values that include an @import directive and other script injection vectors. The vulnerability is triggered when a user views a crafted e-mail message in the Classic UI, requiring no additional user interaction.

⚠️

Confirmed Active Exploitation

This vulnerability is listed in the CISA KEV Catalog. Federal agencies are mandated to patch immediately. Immediate remediation is required.

Exploitation Probability (EPSS)

Low Priority
1.76%

The Exploit Prediction Scoring System (EPSS) uses machine learning to estimate the probability that a vulnerability will be exploited in the wild within the next 30 days.

0% (Theoretical)100% (Certainty)

7-Day Exploitation Trend

Vulnerability Timeline

5 events
Jun 23, 2025
Vulnerability Disclosed
Published to component-level vulnerability database.
Jul 11, 2025
Last Updated
Record updated with new analysis or tags.
May 5, 2026
Added to CISA KEV
CVE added to CISA Known Exploited Vulnerabilities
May 5, 2026
EPSS Score Increased
Daily EPSS score increased by 0.187 on 2025-06-25
Jun 16, 2026
EPSS Score Decreased
Daily EPSS score decreased by 0.164 on 2025-06-25

Threat Actor Attribution

PREMIUM INTEL
Associated Groups:Lazarus Group, APT28
Ransomware Campaigns:LockBit 3.0, BlackCat
IoCs (Indicators):14 IPs, 3 Hashes

Remediation & Mitigation

SOLUTION

Official patches and mitigation steps are available for this vulnerability.

# Update Command
apt-get update && apt-get upgrade -y specific-package
# Verify installation
dpkg -l | grep package-name

Affected Products

3 Total
synacor/zimbra_collaboration_suiteAll Versions
synacor/zimbra_collaboration_suite8.8.15
synacor/zimbra_collaboration_suite9.0.0

Am I Vulnerable?

Check your domain or package.json for CVE-2025-48700 exposure.

Share This Page

Help others discover this vulnerability information

Vulnerability Details

CVSS Base Score
6.1/ 10
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Published Date
Jun 23, 2025
Last Modified
Jul 11, 2025
Need API Access?

Integrate this data into your SOAR platform.

View Plans →
Need Manual Validation?

Automated scanners flag false positives. Get a manual pentest validation for this CVE.