HomeUpdatesZimbra fixes XSS, XXE & LDAP Injection vulnerabilities

Zimbra patches XSS, XXE & LDAP Injection vulnerabilities

A particularly important development occurred in the field of cybersecurity and corporate email infrastructures, after Zimbra released version 10.1.16, which fixes high-severity vulnerabilities that could be exploited in real attacks.

Zimbra vulnerabilities

The new version addresses security vulnerabilities such as cross-site scripting (XSS), XML external entity (XXE) , and LDAP injection, which are considered by experts to be particularly dangerous for organizations that rely on Zimbra deployments for their daily communication.

The company characterizes the update as "high risk" and "high priority," urging administrators to immediately upgrade to protect their systems from potential exploits.

XSS Fixes: Shielding Against Web-Based Attacks

One of the most serious fixes concerns an XSS vulnerability in Webmail 's file sharing features and the Briefcase tool .

See also: Microsoft fixes serious vulnerability in Notepad

In such attacks, attackers can insert malicious scripts through unsanitized inputs, leading to the theft of user sessions, data interception , or even the complete compromise of email accounts.

With the new version, Zimbra has significantly strengthened its login validation mechanisms, blocking such attempts and restoring the security of the web platform without affecting functionality.

XXE in SOAP endpoint: File access and DoS risk

A second critical issue, which was fixed, is an XXE vulnerability in the SOAP endpoint of Exchange Web Services (EWS).

XXE attacks allow hackers to manipulate XML data, aiming to read server files or cause denial-of-service (DoS) via external entities extension.

Zimbra patches XSS, XXE & LDAP Injection vulnerabilities

Zimbra has strengthened XML parsing, preventing entity expansion and ensuring that EWS operations remain secure against such techniques.

LDAP Injection: Dangerous threat to authorized users

Particular attention was also paid to an LDAP injection related to authenticated users.

In this case, insufficient input sanitization could allow an attacker with valid credentials to manipulate LDAP queries, leading to privilege escalation or data directory

See also: Apple fixes zero-day affecting many of its devices

The fix closes a serious "internal" risk, which is often exploited in targeted attacks against organizations.

Additional improvements: CSRF protection and safer previews

In addition to the core vulnerabilities, version 10.1.16 also includes additional security benefits. These include:

  • restored PDF previews in Classic UI with new security controls
  • stronger defense against CSRF attacks through better token validation

These measures reduce the chances of unauthorized actions through deceptive requests.

Zimbra patches XSS, XXE & LDAP Injection vulnerabilities

Performance upgrades and new features

Zimbra didn't just focus on security. The new version also brings significant improvements to Backup & Restore, offering:

  • up to 50% faster backup process
  • 45% less storage space through Zstandard compression
  • deduplication for S3 and external storage systems

At the same time, the modern web application gains new tools such as email translation (Chrome-only), smarter search, custom label colors, and Zoom integration.

There is also beta support for Ubuntu 24, although it is not yet recommended for production environments.

See also: Ivanti patches vulnerabilities in Endpoint Manager (EPM)

What should administrators do now?

Zimbra recommends that administrators test the upgrade in a staging environment first, as this is a high-risk deployment patch. However, delaying the installation of such updates is often the cause of serious breaches.

Version 10.1.16 is a prime example of how critical timely security updates are, especially in email systems that remain among the most targeted targets of cybercriminals.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS