CVE-2018-6882
KEV ransomware PoC massCross-Site Scripting (XSS) in Synacor Zimbra Collaboration Suite
CISA: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting flaw (CWE-79) that allows remote attackers to inject arbitrary web script or HTML through the ZCS web interface. An attacker who successfully injects script can execute it in the browser context of a logged-in Zimbra user, enabling actions such as stealing session cookies or credentials, defacing webmail content, or chaining into further compromise; the specific injection vector is not detailed in the available data. Any organization running Zimbra Collaboration Suite, particularly deployments exposing the ZCS webmail interface to the internet, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-19 with known ransomware use, and EPSS estimates a 25.3% probability of exploitation within 30 days (98th percentile), although no public proof-of-concept is known.
What to do: Apply the latest Zimbra Collaboration Suite patches per Synacor's vendor instructions, as required by CISA's KEV listing, prioritizing internet-facing webmail servers given confirmed in-the-wild exploitation and known ransomware use. Because the affected version range is not specified in this data, check your current ZCS release against Synacor's advisory and upgrade to any patched release it designates. In the interim, restrict exposure of the ZCS web interface and monitor for unexpected injected script or HTML in webmail content.
| Synacor Zimbra Collaboration Suite (ZCS) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.
- Affected
- Synacor Zimbra Collaboration Suite (ZCS)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- synacor
- Products
- zimbra collaboration suite
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N