CVE-2018-6882

MEDIUM KEV RANSOMWARE NUCLEI

Synacor Zimbra Collaboration Suite < 8.7.0 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.

Nuclei Templates (1)

Zimbra Collaboration Suite - Cross-site Scripting
MEDIUMVERIFIEDby Sourabh-Sahu

Scores

CVSS v3 6.1
EPSS 0.7952
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CISA KEV 2022-04-19
VulnCheck KEV 2022-04-14
InTheWild.io 2022-04-14
ENISA EUVD EUVD-2018-18627
Ransomware Use Confirmed
CWE
CWE-79
Status published
Products (9)
synacor/zimbra_collaboration_suite 8.7.0
synacor/zimbra_collaboration_suite 8.8.0
synacor/zimbra_collaboration_suite 8.8.1
synacor/zimbra_collaboration_suite 8.8.2
synacor/zimbra_collaboration_suite 8.8.3
synacor/zimbra_collaboration_suite 8.8.4
synacor/zimbra_collaboration_suite 8.8.5
synacor/zimbra_collaboration_suite 8.8.6
synacor/zimbra_collaboration_suite < 8.7.0
Published Mar 27, 2018
KEV Added Apr 19, 2022
Tracked Since Feb 18, 2026