CVE-2018-6882: Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.
Other sources
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zimbra Collaboration Suite (ZCS)to a version that resolves this vulnerability.Fixed in 8.7 Patch 1Patch 8.7 Patch 1 - Upgrade
Upgrade
Zimbra Collaboration Suite (ZCS)to a version that resolves this vulnerability.Fixed in 8.8.7Patch 8.8.7
Event History
Frequently Asked Questions
What is CVE-2018-6882?
CVE-2018-6882 is a cross-site scripting (XSS) vulnerability in the Zimbra Collaboration Suite (ZCS).
How does the CVE-2018-6882 vulnerability affect Zimbra Collaboration Suite (ZCS)?
The CVE-2018-6882 vulnerability allows remote attackers to inject arbitrary web script or HTML through a Content-Location header in an email attachment in Zimbra Collaboration Suite (ZCS) versions before 8.7 Patch 1 and 8.8.x before 8.8.7.
What is the severity of CVE-2018-6882?
The severity of CVE-2018-6882 is medium with a CVSS score of 6.1.
How can I fix the CVE-2018-6882 vulnerability?
To fix the CVE-2018-6882 vulnerability, update Zimbra Collaboration Suite (ZCS) to version 8.7 Patch 1 or 8.8.7 or later.
Where can I find more information about the CVE-2018-6882 vulnerability?
You can find more information about the CVE-2018-6882 vulnerability at the following references: http://seclists.org/fulldisclosure/2018/Mar/52, http://www.securityfocus.com/archive/1/541891/100/0/threaded, https://bugzilla.zimbra.com/show_bug.cgi?id=108786.