VulnerabilityModified
CVE-2017-8802
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.8.0 Beta2 might allow remote attackers to inject arbitrary web script or HTML via vectors related to the "Show Snippet" functionality.
MEDIUM 5.4EPSS 1.27%
Does this matter?
Lower severity and a low EPSS score (1.27%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.8.0 Beta2 might allow remote attackers to inject arbitrary web script or HTML via vectors related to the "Show Snippet" functionality.
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.27% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- synocor/zimbra collaboration suite
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/archive/1/541661/100/0/threaded
- https://bugzilla.zimbra.com/show_bug.cgi?id=107925Permissions Required
- https://wiki.zimbra.com/wiki/Zimbra_Security_AdvisoriesPatch, Vendor Advisory
- https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2018-001_zimbra_stored_xss.txtThird Party Advisory
- http://www.securityfocus.com/archive/1/541661/100/0/threaded
- https://bugzilla.zimbra.com/show_bug.cgi?id=107925Permissions Required
- https://wiki.zimbra.com/wiki/Zimbra_Security_AdvisoriesPatch, Vendor Advisory
- https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2018-001_zimbra_stored_xss.txtThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.