CVE-2022-24682
KEV RANSOMWAREMEDIUM 6.1EPSS 30.9%
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.
- CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N - EPSS
- 30.93% chance of exploitation in the next 30 days, 98th percentile
- CISA KEV
- added 2022-02-25, used in ransomware campaigns
- Nuclei
- medium · CWE-116
- Published
- 2022-02-09
- Updated
- 2026-08-07
Proof-of-concept exploits (2)
- https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitation-of-zero…
- https://blog.zimbra.com/2022/02/hotfix-available-5-feb-for-zero-day-exploit-vulnerability…