CVE-2018-6882
בינונית 6.1 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.
מדדים
- CVSS 3.1
-
6.1 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 24% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-79
מוצרים מושפעים
synacor: zimbra collaboration suite
קישורים
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories Vendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories Vendor Advisory
- https://www.securify.nl/advisory/SFY20180101/cross-site-scripting-vulnerabilit… ExploitThird Party Advisory
- https://www.securify.nl/advisory/SFY20180101/cross-site-scripting-vulnerabilit… ExploitThird Party Advisory
- http://seclists.org/fulldisclosure/2018/Mar/52 Mailing ListThird Party Advisory
- http://www.securityfocus.com/archive/1/541891/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
- https://bugzilla.zimbra.com/show_bug.cgi?id=108786 Broken LinkIssue TrackingPermissions Required
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.7 Permissions Required
- http://seclists.org/fulldisclosure/2018/Mar/52 Mailing ListThird Party Advisory
- http://www.securityfocus.com/archive/1/541891/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry