CVE-2018-6882
Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
YesDecision
Descriptions
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.
Vulnerabilidad de Cross-Site Scripting (XSS) en la función ZmMailMsgView.getAttachmentLinkHtml en Zimbra Collaboration Suite (ZCS), en versiones anteriores a la 8.7 Patch 1 y versiones 8.8.x anteriores a la 8.8.7, podría permitir que atacantes remotos inyecten scripts web o HTML arbitrarios mediante una cabecera Content-Location en un adjunto de correo electrónico.
Zimbra Collaboration Suite version 8.7.11_GA_1854 suffers from a cross site scripting vulnerability.
Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-02-09 CVE Reserved
- 2018-03-25 CVE Published
- 2022-04-19 Exploited in Wild
- 2022-05-10 KEV Due Date
- 2023-10-21 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2018/Mar/52 | Mailing List | |
http://www.securityfocus.com/archive/1/541891/100/0/threaded | Mailing List | |
https://bugzilla.zimbra.com/show_bug.cgi?id=108786 | Issue Tracking |
URL | Date | SRC |
---|---|---|
https://www.securify.nl/advisory/SFY20180101/cross-site-scripting-vulnerability-in-zimbra-collaboration-suite-due-to-the-way-it-handles-attachment-links.html | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | 2019-03-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | < 8.7 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version " < 8.7" | - |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 8.7 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "8.7" | - |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 8.8.0 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "8.8.0" | - |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 8.8.1 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "8.8.1" | - |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 8.8.2 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "8.8.2" | - |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 8.8.3 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "8.8.3" | - |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 8.8.4 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "8.8.4" | - |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 8.8.5 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "8.8.5" | - |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 8.8.6 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "8.8.6" | - |
Affected
|