Junglewise Threat Intelligence

CVE-2016-3409: Zimbra Collaboration XSS in unspecified components

CVE-2016-3409 · Severity: medium · CVSS 6.1 · Published 2017-01-18

Technologies: Synacor Zimbra Collaboration Suite, Zimbra Collaboration. Vendors: Synacor, Zimbra.

Executive brief

Zimbra Collaboration is an enterprise-grade email and collaboration platform. A security vulnerability in versions prior to 8.7.0 allows remote attackers to perform cross-site scripting (XSS) attacks. If exploited, an attacker could execute malicious scripts in a user's browser session, potentially leading to the theft of session cookies, unauthorized access to email accounts, or the manipulation of web content.

Technical details

A cross-site scripting (XSS) vulnerability exists in Zimbra Collaboration (formerly Zimbra Collaboration Suite) in versions prior to 8.7.0. The flaw allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, identified internally by Zimbra as bug 102637. The vulnerability is network-reachable and requires some level of user interaction (UI:R), such as a user clicking a malicious link or viewing a crafted email. Successful exploitation allows an attacker to execute code in the context of the victim's browser session, which can lead to information disclosure or session hijacking. The issue was addressed in the Zimbra Collaboration 8.7.0 GA release.

Affected products

  • Zimbra Zimbra Collaboration before 8.7.0

Timeline

  • 2016-01-01: patched: Fixed in Zimbra Collaboration 8.7.0 GA release
  • 2017-01-18: disclosed: NVD publication date

References

Related threats