vulnerability

Zimbra Collaboration: CVE-2018-6882: Persistent XSS CWE-79

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Mar 27, 2018
Added
Jan 10, 2025
Modified
Jul 17, 2025

Description

Cross-site scripting (xss) vulnerability in the zmmailmsgview.getattachmentlinkhtml function in zimbra collaboration suite (zcs) before 8.7 patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or html via a content-location header in an email attachment.

Solution

zimbra-collaboration-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.