Junglewise Threat Intelligence

CVE-2018-6882: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

CVE-2018-6882 · Severity: critical · CVSS 6.1 · Exploited in the wild · Published 2022-04-19

Technologies: Synacor Zimbra Collaboration Suite (ZCS). Vendors: Synacor.

Executive brief

A cross-site scripting (XSS) vulnerability exists in the ZmMailMsgView.getAttachmentLinkHtml function of Zimbra Collaboration Suite. Remote attackers can inject arbitrary web script or HTML via a malicious Content-Location header in an email attachment.

Affected products

  • Synacor Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1, 8.8.x before 8.8.7

Timeline

  • 2018-03-20: disclosed: Initial public disclosure via Securify advisory and mailing lists.
  • 2022-04-19: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.

Related threats