Junglewise Threat Intelligence

CVE-2016-3411: Zimbra Collaboration XSS in changepass component

CVE-2016-3411 · Severity: medium · CVSS 6.1 · Published 2017-01-18

Technologies: Synacor Zimbra Collaboration Suite, Zimbra Collaboration. Vendors: Synacor, Zimbra.

Executive brief

Zimbra Collaboration is a widely used enterprise email and collaboration platform. A security flaw in the web interface allows remote attackers to inject malicious scripts into a user's session. If a user visits a specially crafted link, an attacker could potentially steal login credentials, hijack the user's session, or perform unauthorized actions on their behalf within the email system.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the Zimbra Collaboration web interface, specifically within the /h/changepass endpoint. The vulnerability is caused by improper neutralization of user-supplied input in the 'skin' parameter, which is reflected back into the HTML response without adequate sanitization. An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious URL containing a JavaScript payload. Successful exploitation allows the attacker to execute arbitrary code in the context of the victim's browser session, potentially leading to session token theft or unauthorized administrative actions. This issue was addressed in Zimbra Collaboration version 8.7.0.

Affected products

  • Zimbra Collaboration before 8.7.0

Timeline

  • 2016-03-01: other: Internal bug 103609 reported to vendor
  • 2017-01-18: disclosed: NVD publication date
  • 2018-08-10: other: Public exploit payload published on Exploit-DB

References

Related threats