Back

MEDIUM KEV Used in ransomware campaigns

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment

Published Mar 27, 2018 ·Due May 10, 2022

Description

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (4)
  1. CISA ADP
    • SSVC technical impact changed from partial to total
  2. CISA ADP
    • SSVC technical impact changed from total to partial
  3. CISA ADP
    • SSVC technical impact changed from partial to total
  4. CISA ADP
    • SSVC technical impact changed from total to partial
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 27, 2018
Updated Oct 1, 2026
Reserved Feb 9, 2018
CISA Vulnrichment
Updated Aug 13, 2026
NVD
Status Analyzed
Modified Aug 13, 2026
Red Hat
Severity n/a
Public date n/a