Junglewise Threat Intelligence

CVE-2016-3999: Zimbra Collaboration multiple XSS vulnerabilities

CVE-2016-3999 · Severity: medium · CVSS 6.1 · Published 2017-01-18

Technologies: Synacor Zimbra Collaboration Suite, Zimbra Collaboration Suite. Vendors: Synacor, Zimbra.

Executive brief

Zimbra Collaboration is a widely used enterprise email and collaboration platform. Multiple vulnerabilities in versions prior to 8.7.0 allow remote attackers to inject malicious scripts into the web interface. If a user views a specially crafted page or email, an attacker could potentially steal login credentials, hijack user sessions, or perform actions on behalf of the user.

Technical details

Multiple cross-site scripting (XSS) vulnerabilities exist in Zimbra Collaboration Suite (ZCS) prior to version 8.7.0. The flaws, identified internally as bugs 104552 and 104703, stem from improper neutralization of user-supplied input during web page generation (CWE-79). A remote, unauthenticated attacker can exploit these vulnerabilities by enticing a user to interact with a malicious link or view crafted content, leading to the execution of arbitrary JavaScript in the context of the victim's browser session. This can result in session hijacking or unauthorized access to sensitive user data. The issues are resolved in Zimbra Collaboration 8.7.0.

Affected products

  • Zimbra Zimbra Collaboration Suite before 8.7.0

Timeline

  • 2016-03-31: disclosed: CVE assigned
  • 2017-01-18: advisory: NVD publication date

References

Related threats