CVE-2016-3408: XSS
Published Jan 18, 2017
·Updated
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bug 101813.
Affected Software
1 affected component
Synacor Zimbra Collaboration Suite<=8.6.0
Event History
Jan 18, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-3408?
CVE-2016-3408 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2016-3408?
To fix CVE-2016-3408, upgrade Zimbra Collaboration to version 8.7.0 or later.
3
What systems are affected by CVE-2016-3408?
CVE-2016-3408 affects Zimbra Collaboration Suite versions prior to 8.7.0.
4
What types of attacks can be performed using CVE-2016-3408?
Attackers can exploit CVE-2016-3408 to inject arbitrary web scripts or HTML into web pages viewed by users.
5
Is there a workaround for CVE-2016-3408 if I cannot upgrade immediately?
There are no official workarounds for CVE-2016-3408; upgrading to a patched version is the recommended solution.