CVE-2018-6882

CVE Published 2018-03-27
Related CWE(s) CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Related Vendor(s) synacor
Related Product(s) zimbra_collaboration_suite
Exploitation Reported (CISA KEV) 2022-04-19
CVSS 3 Base Score 6.1 (MEDIUM)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References