QID 376708
Date Published: 2022-07-06
QID 376708: Zimbra Collaboration Suite Cross-Site Scripting (XSS) Vulnerability
Zimbra is a complete email, address book, calendar and tasks solution that can be accessed from the Zimbra Web Client, Zimbra Desktop offline client, Outlook and a variety of other standards-based email clients and mobile devices.
Affected Software:
Zimbra Collaboration Suite before 8.7p1
Zimbra Collaboration Suite 8.8.x before 8.8.7
QID Detection Logic:
This QID runs "zmcontrol -v" to check the vulnerable version
It allows remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.
Solution
Vendor has released patched versions Zimbra 8.8.15p30, 9.0.0p16 to fix this issue. For more details please refer to Zimbra 8.8.7
Vendor References
- Zimbra Security_Advisory -
wiki.zimbra.com/wiki/Zimbra_Security_Advisories
CVEs related to QID 376708
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2018-6882 |
|