CVE-2018-6882

KEV
🔴 Łataj teraz

Luka XSS w Zimbra Collaboration Suite umożliwia zdalne wstrzyknięcie skryptu przez załącznik.

CVSS
6.1
EPSS
25.4%
Exploit
weaponized
Vendor
synacor
Opis źródłowy (NVD)

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.

exploit xss Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.1
CISA KEV (aktywnie wykorzystywane)Tak
FIRST EPSS (prawdopodobieństwo exploita)25.4%
Opublikowano (NVD)2018-03-27 16:29:00 UTC
Ostatnia modyfikacja (NVD)2026-08-13 05:17:18 UTC
Referencje