CVE-2016-5721: XSS
Published Aug 29, 2016
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
Zimbra Zimbra Collaboration Server<=8.6.0
Event History
Aug 29, 2016
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5721?
CVE-2016-5721 has a high severity rating due to its potential for exploitation through multiple cross-site scripting vulnerabilities.
2
How do I fix CVE-2016-5721?
To fix CVE-2016-5721, upgrade to Zimbra Collaboration version 8.7.0 or later.
3
What types of attacks are possible with CVE-2016-5721?
CVE-2016-5721 allows remote attackers to inject arbitrary web script or HTML, leading to potential phishing or session hijacking attacks.
4
Which versions of Zimbra Collaboration are affected by CVE-2016-5721?
CVE-2016-5721 affects Zimbra Collaboration Server versions up to and including 8.6.0.
5
Is authentication required to exploit CVE-2016-5721?
CVE-2016-5721 can be exploited remotely without authentication, making it particularly dangerous.