ZeroHour

CVE-2018-6882

KEV ransomware PoC mass

Cross-Site Scripting (XSS) in Synacor Zimbra Collaboration Suite

CISA: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

CVSS 3.1
6.1 medium
EPSS
25%p98
Published
()
KEV added
AI analysis

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting flaw (CWE-79) that allows remote attackers to inject arbitrary web script or HTML through the ZCS web interface. An attacker who successfully injects script can execute it in the browser context of a logged-in Zimbra user, enabling actions such as stealing session cookies or credentials, defacing webmail content, or chaining into further compromise; the specific injection vector is not detailed in the available data. Any organization running Zimbra Collaboration Suite, particularly deployments exposing the ZCS webmail interface to the internet, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-19 with known ransomware use, and EPSS estimates a 25.3% probability of exploitation within 30 days (98th percentile), although no public proof-of-concept is known.

What to do: Apply the latest Zimbra Collaboration Suite patches per Synacor's vendor instructions, as required by CISA's KEV listing, prioritizing internet-facing webmail servers given confirmed in-the-wild exploitation and known ransomware use. Because the affected version range is not specified in this data, check your current ZCS release against Synacor's advisory and upgrade to any patched release it designates. In the interim, restrict exposure of the ZCS web interface and monitor for unexpected injected script or HTML in webmail content.

Affected
Synacor Zimbra Collaboration Suite (ZCS)
Estimated exposure
mass≈ millions of users across tens of thousands of internet-exposed ZCS servers (estimate; public internet-wide scans of Zimbra deployments) — Independent internet-wide scans (e.g., Shodan/Censys-style scans) have repeatedly shown tens of thousands of publicly reachable Zimbra Collaboration Suite servers, and each such deployment typically serves hundreds of mailboxes, plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.

CISA Known Exploited Vulnerability
Affected
Synacor Zimbra Collaboration Suite (ZCS)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
synacor
Products
zimbra collaboration suite
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news