Junglewise Threat Intelligence

CVE-2016-3408: Zimbra Collaboration XSS in unspecified component

CVE-2016-3408 · Severity: medium · CVSS 6.1 · Published 2017-01-18

Technologies: Synacor Zimbra Collaboration Suite, Zimbra Collaboration. Vendors: Synacor, Zimbra.

Executive brief

Zimbra Collaboration is an enterprise-grade email and collaboration platform. A security vulnerability in versions prior to 8.7.0 allows remote attackers to perform cross-site scripting (XSS) attacks. If exploited, an attacker could execute malicious scripts in a user's browser session, potentially leading to the theft of login credentials, unauthorized access to emails, or the hijacking of user accounts.

Technical details

A cross-site scripting (XSS) vulnerability exists in Zimbra Collaboration (formerly Zimbra Collaboration Suite) in versions prior to 8.7.0. The flaw is rooted in improper neutralization of user-supplied input during web page generation (CWE-79). A remote, unauthenticated attacker can exploit this by enticing a user to visit a specially crafted URL or interact with malicious HTML content. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can be used to bypass same-origin policy protections and access sensitive session data. This issue is tracked internally by Zimbra as bug 101813 and was addressed in the 8.7.0 GA release.

Affected products

  • Zimbra Collaboration before 8.7.0

Timeline

  • 2016-01-01: patched: Zimbra Collaboration 8.7.0 released
  • 2017-01-18: disclosed: NVD publication date

References

Related threats