CVE-2016-3409: XSS
Published Jan 18, 2017
·Updated
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bug 102637.
Affected Software
1 affected component
Synacor Zimbra Collaboration Suite<=8.6.0
Event History
Jan 18, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-3409?
The severity of CVE-2016-3409 is rated as high due to its potential to allow remote attackers to execute arbitrary scripts.
2
How do I fix CVE-2016-3409?
To fix CVE-2016-3409, upgrade to Zimbra Collaboration version 8.7.0 or later.
3
Who is affected by CVE-2016-3409?
CVE-2016-3409 affects Zimbra Collaboration Suite versions prior to 8.7.0.
4
What type of vulnerability is CVE-2016-3409?
CVE-2016-3409 is a cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2016-3409?
Attackers exploiting CVE-2016-3409 can inject arbitrary web scripts or HTML into affected applications.