CVE-2018-6882
MEDIUM(6.1)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- CVSS 6.1 — Mittel
- Im CISA KEV-Katalog (aktiv ausgenutzt)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
25.3%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
6.1
Technische Schwere
SecBoard-Einordnung
CVE-2018-6882 beschreibt eine Cross-Site-Scripting (XSS)-Schwachstelle in der ZmMailMsgView.getAttachmentLinkHtml-Funktion der Zimbra Collaboration Suite (ZCS). Diese Schwachstelle ermöglicht es Angreifern, über einen manipulierten Content-Location-Header in einem E-Mail-Anhang beliebigen Web-Skriptcode oder HTML einzuschleusen. Die erfolgreiche Ausnutzung kann zur Ausführung von Skripten im Browser des Benutzers führen, was Session-Hijacking oder das Einschleusen bösartiger Inhalte ermöglicht.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.
Betroffene Produkte
- cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*
- cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.0:-:*:*:*:*:*:*
- cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.0:*:*:*:*:*:*:*
- cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.1:*:*:*:*:*:*:*
- cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.2:*:*:*:*:*:*:*
- cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.3:*:*:*:*:*:*:*
- cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.4:*:*:*:*:*:*:*
- cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.5:*:*:*:*:*:*:*
- cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.6:*:*:*:*:*:*:*
Referenzen
- http://seclists.org/fulldisclosure/2018/Mar/52
- http://www.securityfocus.com/archive/1/541891/100/0/threaded
- https://bugzilla.zimbra.com/show_bug.cgi?id=108786
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.7
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- https://www.securify.nl/advisory/SFY20180101/cross-site-scripting-vulnerability-...
- http://seclists.org/fulldisclosure/2018/Mar/52
- http://www.securityfocus.com/archive/1/541891/100/0/threaded
- https://bugzilla.zimbra.com/show_bug.cgi?id=108786
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.7