Junglewise Threat Intelligence

CVE-2016-3412: Zimbra Collaboration Multiple XSS Vulnerabilities

CVE-2016-3412 · Severity: medium · CVSS 6.1 · Published 2017-01-18

Technologies: Synacor Zimbra Collaboration Suite, Zimbra Collaboration. Vendors: Synacor, Zimbra.

Executive brief

Multiple security flaws in Zimbra Collaboration could allow an attacker to run malicious scripts in a user's web browser. Zimbra is a widely used email and collaboration platform; if exploited, these vulnerabilities could allow an attacker to steal session cookies, hijack user accounts, or access sensitive communications. This issue affects all versions of the software prior to 8.7.0.

Technical details

Zimbra Collaboration versions prior to 8.7.0 are affected by multiple cross-site scripting (XSS) vulnerabilities (identified internally as bugs 103997, 104413, 104414, 104777, and 104791). The root cause is improper neutralization of user-supplied input during web page generation (CWE-79). A remote, unauthenticated attacker can exploit these flaws by enticing a user to view a specially crafted page or email, leading to the execution of arbitrary JavaScript in the context of the victim's browser session. This can result in the theft of authentication tokens or unauthorized actions performed on behalf of the user. The vulnerabilities were addressed in the Zimbra Collaboration 8.7.0 GA release.

Affected products

  • Zimbra Zimbra Collaboration before 8.7.0

Timeline

  • 2016-07-01: patched: Zimbra Collaboration 8.7.0 released
  • 2017-01-18: disclosed: NVD publication date

References

Related threats