Executive brief
Multiple security flaws in Zimbra Collaboration could allow an attacker to run malicious scripts in a user's web browser. Zimbra is a widely used email and collaboration platform; if exploited, these vulnerabilities could allow an attacker to steal session cookies, hijack user accounts, or access sensitive communications. This issue affects all versions of the software prior to 8.7.0.
Technical details
Zimbra Collaboration versions prior to 8.7.0 are affected by multiple cross-site scripting (XSS) vulnerabilities (identified internally as bugs 103997, 104413, 104414, 104777, and 104791). The root cause is improper neutralization of user-supplied input during web page generation (CWE-79). A remote, unauthenticated attacker can exploit these flaws by enticing a user to view a specially crafted page or email, leading to the execution of arbitrary JavaScript in the context of the victim's browser session. This can result in the theft of authentication tokens or unauthorized actions performed on behalf of the user. The vulnerabilities were addressed in the Zimbra Collaboration 8.7.0 GA release.
Affected products
- Zimbra Zimbra Collaboration before 8.7.0
Timeline
- 2016-07-01: patched: Zimbra Collaboration 8.7.0 released
- 2017-01-18: disclosed: NVD publication date