An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists through the Briefcase module due to improper sanitization of file content by the OnlyOffice formatter. This occurs when the victim opens a crafted URL pointing to a shared folder containing a malicious file uploaded by the attacker. The vulnerability allows the attacker to execute arbitrary JavaScript in the context of the victim's session.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/45xxx/CVE-2024-45511.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "10.1"
}
],
"source": "DESCRIPTION"
}
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "10.0.9"
},
{
"introduced": "10.1.0"
},
{
"last_affected": "10.1.0"
}
],
"cpe": [
"cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*",
"cpe:2.3:a:synacor:zimbra_collaboration_suite:10.1.0:*:*:*:*:*:*:*"
],
"source": [
"CPE_RANGE",
"CPE_STRING"
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "10.0.9"
},
{
"introduced": "10.1.0"
},
{
"last_affected": "10.1.0"
}
],
"cpe": [
"cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*",
"cpe:2.3:a:synacor:zimbra_collaboration_suite:10.1.0:*:*:*:*:*:*:*"
],
"source": [
"CPE_RANGE",
"CPE_STRING"
]
}[
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 5736.0,
"function_hash": "339825474323013521183241826067317574250"
},
"id": "CVE-2024-45511-8f36f92c",
"signature_type": "Function",
"source": "https://github.com/zimbra/zm-mailbox/commit/a28371d6e77de652833e208a1c9d074f94ce36b4",
"target": {
"function": "handle",
"file": "store/src/java/com/zimbra/cs/service/mail/SaveDraft.java"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"337470034528614112051626076596091448768",
"206270029150699549176038490143151665801",
"255655912282109743755918710405709077885",
"171140784898272639202458916621426570256",
"262462816086553384881380158886169568146",
"287611038658038860516445880220323716532",
"95583691136116369616283734961458578373",
"221345564213786407153003906878025552530",
"129748365095992762317287749407585651371",
"163399839941821719543073122398703135171",
"155115778877998026564944218407819867158",
"252471202034437300847526430791461390849",
"31183811373230877232121826966060017583",
"316922818180324272441484121178638670636",
"137462080993319077135314138404951881241",
"188451475134819477117520408427906260665",
"25905982176558177072602329661744824783",
"132256262233950813561871574055221766980",
"319528592402864069938419172276206493032",
"143967281866102560867614478337965332463",
"89392272245757324774762688710421788068",
"230557637083376737053396039573273702338",
"197622903459566510185545266964825375464",
"217416885986732144975404456334001328503",
"153906800503353549862306626428652610342"
]
},
"id": "CVE-2024-45511-ae8bbb51",
"signature_type": "Line",
"source": "https://github.com/zimbra/zm-mailbox/commit/a28371d6e77de652833e208a1c9d074f94ce36b4",
"target": {
"file": "store/src/java/com/zimbra/cs/service/mail/SaveDraft.java"
}
}
]
"2026-07-22T03:35:31Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-45511.json"
{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "10.0.9"
},
{
"introduced": "10.1.0"
},
{
"last_affected": "10.1.0"
}
],
"cpe": [
"cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*",
"cpe:2.3:a:synacor:zimbra_collaboration_suite:10.1.0:*:*:*:*:*:*:*"
],
"source": [
"CPE_RANGE",
"CPE_STRING"
]
}