{"id":"CVE-2024-45511","details":"An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists through the Briefcase module due to improper sanitization of file content by the OnlyOffice formatter. This occurs when the victim opens a crafted URL pointing to a shared folder containing a malicious file uploaded by the attacker. The vulnerability allows the attacker to execute arbitrary JavaScript in the context of the victim's session.","modified":"2026-08-12T15:15:32.413079Z","published":"2024-11-20T00:00:00Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"fixed":"10.1"}],"source":"DESCRIPTION"}],"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/45xxx/CVE-2024-45511.json"},"references":[{"type":"WEB","url":"https://wiki.zimbra.com/wiki/Security_Center"},{"type":"WEB","url":"https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.9#Security_Fixes"},{"type":"WEB","url":"https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.1#Security_Fixes"},{"type":"WEB","url":"https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/45xxx/CVE-2024-45511.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-45511"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-build","events":[{"introduced":"0"},{"fixed":"2c67cbdfaebf6a71928749b7146f4852876b63ff"},{"introduced":"52b539ef205db233bfd8116e8130e27735b4153c"},{"last_affected":"52b539ef205db233bfd8116e8130e27735b4153c"}],"database_specific":{"cpe":["cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*","cpe:2.3:a:synacor:zimbra_collaboration_suite:10.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"10.0.9"},{"introduced":"10.1.0"},{"last_affected":"10.1.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["10.1.0","10.0.6","10.0.5","10.0.4","10.0.1","10.0.0-GA","10.0.0","9.0.0","8.8.12","8.8.10","8.8.9.p3","8.8.9.p1","8.8.9","8.8.8","8.7.11","8.8.7","8.8.6","8.8.4","8.8.3","8.8.2","8.8.0.beta1","8.7.10","8.7.9","8.7.7","8.7.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-45511.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-mailbox","events":[{"introduced":"0"},{"fixed":"a28371d6e77de652833e208a1c9d074f94ce36b4"},{"introduced":"de2f187263204c5edbcd64ab4aad155367f27eef"},{"last_affected":"de2f187263204c5edbcd64ab4aad155367f27eef"}],"database_specific":{"cpe":["cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*","cpe:2.3:a:synacor:zimbra_collaboration_suite:10.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"10.0.9"},{"introduced":"10.1.0"},{"last_affected":"10.1.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["10.1.0","10.0.8","10.0.0","10.0.7","10.0.6","10.0.5","10.0.2","10.0.1","10.0.0-GA","9.0.0","8.8.8","8.8.12","8.8.10","8.8.9","8.8.7","8.8.6","8.8.5","8.8.4","8.8.3","8.8.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-45511.json","vanir_signatures_modified":"2026-08-12T15:15:32Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/zimbra/zm-mailbox/commit/a28371d6e77de652833e208a1c9d074f94ce36b4","target":{"file":"store/src/java/com/zimbra/cs/service/mail/SaveDraft.java","function":"handle"},"deprecated":false,"digest":{"function_hash":"339825474323013521183241826067317574250","length":5736},"id":"CVE-2024-45511-8f36f92c"},{"digest":{"line_hashes":["337470034528614112051626076596091448768","206270029150699549176038490143151665801","255655912282109743755918710405709077885","171140784898272639202458916621426570256","262462816086553384881380158886169568146","287611038658038860516445880220323716532","95583691136116369616283734961458578373","221345564213786407153003906878025552530","129748365095992762317287749407585651371","163399839941821719543073122398703135171","155115778877998026564944218407819867158","252471202034437300847526430791461390849","31183811373230877232121826966060017583","316922818180324272441484121178638670636","137462080993319077135314138404951881241","188451475134819477117520408427906260665","25905982176558177072602329661744824783","132256262233950813561871574055221766980","319528592402864069938419172276206493032","143967281866102560867614478337965332463","89392272245757324774762688710421788068","230557637083376737053396039573273702338","197622903459566510185545266964825375464","217416885986732144975404456334001328503","153906800503353549862306626428652610342"],"threshold":0.9},"id":"CVE-2024-45511-ae8bbb51","signature_type":"Line","signature_version":"v1","source":"https://github.com/zimbra/zm-mailbox/commit/a28371d6e77de652833e208a1c9d074f94ce36b4","target":{"file":"store/src/java/com/zimbra/cs/service/mail/SaveDraft.java"},"deprecated":false}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-zcs","events":[{"introduced":"5a574c4741e2713147c61524e30057679ece2ec6"},{"last_affected":"5a574c4741e2713147c61524e30057679ece2ec6"}],"database_specific":{"cpe":"cpe:2.3:a:synacor:zimbra_collaboration_suite:10.1.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"10.1.0"},{"last_affected":"10.1.0"}],"source":"CPE_STRING"}}],"versions":["10.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-45511.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-zcs-lib","events":[{"introduced":"0"},{"fixed":"74ca4ff049d001731d7e1a22f667e32ad9a672e1"},{"introduced":"0da199c818c28750b27aec8c2aa1fa8420086d4e"},{"last_affected":"0da199c818c28750b27aec8c2aa1fa8420086d4e"}],"database_specific":{"cpe":["cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*","cpe:2.3:a:synacor:zimbra_collaboration_suite:10.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"10.0.9"},{"introduced":"10.1.0"},{"last_affected":"10.1.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["10.1.0","10.0.1","10.0.0-GA","10.0.0","9.0.0","8.8.12","8.8.11","8.8.10","8.8.9","8.8.8","8.7.11","8.8.7","8.8.6","8.8.5","8.8.4","8.8.3","8.8.2","8.8.0.beta1","8.7.10","8.7.9","8.7.7","8.7.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-45511.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}