Executive brief
Zimbra Collaboration, a widely used enterprise email and collaboration platform, is affected by multiple security flaws that allow attackers to run malicious scripts in a user's browser. By tricking a user into clicking a link or viewing a specially crafted page, an attacker could potentially steal login session information or perform actions on behalf of the user. This could lead to unauthorized access to corporate email accounts and sensitive internal communications.
Technical details
Multiple cross-site scripting (XSS) vulnerabilities exist in Zimbra Collaboration Suite (ZCS) versions prior to 8.7.0. The vulnerabilities, tracked internally by Zimbra as bugs 104222, 104910, 105071, and 105175, stem from improper neutralization of user-supplied input during web page generation. A remote, unauthenticated attacker can exploit these flaws by persuading a user to visit a malicious URL or interact with crafted content. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking, credential theft, or unauthorized administrative actions. The issues are resolved in Zimbra Collaboration 8.7.0 GA.
Affected products
- Zimbra Zimbra Collaboration Suite before 8.7.0
Timeline
- 2017-01-18: advisory: NVD publication date
- 2016-07-13: patched: Zimbra 8.7.0 GA release date