Junglewise Threat Intelligence

CVE-2016-3410: Zimbra Collaboration multiple XSS vulnerabilities

CVE-2016-3410 · Severity: medium · CVSS 6.1 · Published 2017-01-18

Technologies: Synacor Zimbra Collaboration Suite, Zimbra Collaboration. Vendors: Synacor, Zimbra.

Executive brief

Zimbra Collaboration is a widely used enterprise email and collaboration platform. Multiple security flaws in versions prior to 8.7.0 allow attackers to inject malicious scripts into the web interface. If a user views a specially crafted message or page, an attacker could potentially steal session information, access private emails, or perform actions on behalf of the user, compromising the integrity and confidentiality of the organization's communications.

Technical details

Multiple cross-site scripting (XSS) vulnerabilities exist in Zimbra Collaboration (formerly Zimbra Collaboration Suite) versions prior to 8.7.0. The flaws, tracked internally by Zimbra as bugs 103956, 103995, 104475, 104838, and 104839, stem from improper neutralization of user-supplied input during web page generation (CWE-79). A remote, unauthenticated attacker can exploit these vulnerabilities by sending a crafted request or email that, when viewed by a victim, executes arbitrary JavaScript or HTML in the context of the victim's browser session. This can lead to session hijacking, unauthorized data access, or phishing. The issues are resolved in Zimbra Collaboration 8.7.0.

Affected products

  • Zimbra Zimbra Collaboration before 8.7.0

Timeline

  • 2016-03-31: disclosed: CVE assigned
  • 2016-07-13: patched: Zimbra 8.7.0 released
  • 2017-01-18: advisory: NVD publication date

References

Related threats