{"id":"CVE-2026-93647","published":"2026-09-25T14:17:23.673","lastModified":"2026-09-29T21:29:07.663","description":"An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.","cvssScore":9.3,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"A cross-site scripting (XSS) vulnerability allows unauthenticated attackers to inject malicious content into a COUNTER message's RFC From address, leading to potential access to victim's mailbox data.","exploitability":"Exploitation is moderately difficult as it requires the attacker to craft a specific COUNTER message and ensure it is selected by the victim. Precondition is that the Zimbra Classic user must open the message.","blast_radius":"If exploited, the attacker can access sensitive mailbox data and potentially impersonate the victim, leading to significant data breaches.","remediation":"Disable the COUNTER message feature in Zimbra Classic until a patch is available.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["xss","web","mail","unauth"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:50:18.201Z"}}