CVE-2018-6882
MEDIUM KEV RANSOMWARE NUCLEISynacor Zimbra Collaboration Suite < 8.7.0 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.
Nuclei Templates (1)
Zimbra Collaboration Suite - Cross-site Scripting
MEDIUMVERIFIEDby Sourabh-Sahu
References (7)
Scores
CVSS v3
6.1
EPSS
0.7952
EPSS Percentile
99.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CISA KEV
2022-04-19
VulnCheck KEV
2022-04-14
InTheWild.io
2022-04-14
ENISA EUVD
EUVD-2018-18627
Ransomware Use
Confirmed
CWE
CWE-79
Status
published
Products (9)
synacor/zimbra_collaboration_suite
8.7.0
synacor/zimbra_collaboration_suite
8.8.0
synacor/zimbra_collaboration_suite
8.8.1
synacor/zimbra_collaboration_suite
8.8.2
synacor/zimbra_collaboration_suite
8.8.3
synacor/zimbra_collaboration_suite
8.8.4
synacor/zimbra_collaboration_suite
8.8.5
synacor/zimbra_collaboration_suite
8.8.6
synacor/zimbra_collaboration_suite
< 8.7.0
Published
Mar 27, 2018
KEV Added
Apr 19, 2022
Tracked Since
Feb 18, 2026