MIRAGE
Threat IntelligenceCVEs › CVE-2024-27443

CVE-2024-27443 — exposed on the internet

Internet exposure observed by OffSeq scans · last 30 days

6
Exposed hosts
6.1
CVSS
23.6%
EPSS

Found on 6 internet-exposed hosts by OffSeq scans; no in-the-wild exploitation has been observed against OffSeq honeypots in this window.

About CVE-2024-27443

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.

CWE-79

OffSeq internet scanning found CVE-2024-27443 on 6 exposed hosts in the last 30 days. OffSeq honeypots have not recorded in-the-wild exploitation of this CVE in the current window — this page tracks its exposure footprint and status; if exploitation begins, the live honeypot signal will appear here.

Exposed-host countries

Exposed via

zimbra

Open the live CVE-2024-27443 view →

References