First published: Wed Jan 18 2017(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 103997, 104413, 104414, 104777, and 104791.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zimbra Collaboration Suite | <=8.6.0 | |
<=8.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3412 is categorized as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To remediate CVE-2016-3412, upgrade Zimbra Collaboration to version 8.7.0 or later where the vulnerabilities are addressed.
CVE-2016-3412 affects Zimbra Collaboration Suite version 8.6.0 and earlier.
CVE-2016-3412 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject malicious scripts.
Yes, CVE-2016-3412 can be exploited remotely through various unspecified vectors.