VulnerabilityAnalyzed
CVE-2018-6882
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
KEVMEDIUM 6.1EPSS 25.3%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 10 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 25.27% probability · 98th percentile
- CISA KEV
- Listed 19 April 2022 · due 10 May 2022 · used in ransomware campaigns
- Weakness
- CWE-79
- Affected
- synacor/zimbra collaboration suite
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2018-6882
References
- http://seclists.org/fulldisclosure/2018/Mar/52Mailing List, Third Party Advisory
- http://www.securityfocus.com/archive/1/541891/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://bugzilla.zimbra.com/show_bug.cgi?id=108786Broken Link, Issue Tracking, Permissions Required
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.7Permissions Required
- https://wiki.zimbra.com/wiki/Zimbra_Security_AdvisoriesVendor Advisory
- https://www.securify.nl/advisory/SFY20180101/cross-site-scripting-vulnerability-in-zimbra-collaboration-suite-due-to-the-way-it-handles-attachment-links.htmlExploit, Third Party Advisory
- http://seclists.org/fulldisclosure/2018/Mar/52Mailing List, Third Party Advisory
- http://www.securityfocus.com/archive/1/541891/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://bugzilla.zimbra.com/show_bug.cgi?id=108786Broken Link, Issue Tracking, Permissions Required
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.7Permissions Required
- https://wiki.zimbra.com/wiki/Zimbra_Security_AdvisoriesVendor Advisory
- https://www.securify.nl/advisory/SFY20180101/cross-site-scripting-vulnerability-in-zimbra-collaboration-suite-due-to-the-way-it-handles-attachment-links.htmlExploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-6882US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.