VYPR
Medium severity6.1CISA KEVOSV Advisory· Published Mar 27, 2018· Updated Aug 13, 2026

CVE-2018-6882

CVE-2018-6882

Description

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

12
  • Range: 8.7.10, 8.7.11, 8.7.6, …
  • cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*range: <8.7.0
    • cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.0:-:*:*:*:*:*:*
    • cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.2:*:*:*:*:*:*:*
    • cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.3:*:*:*:*:*:*:*
    • cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.4:*:*:*:*:*:*:*
    • cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.5:*:*:*:*:*:*:*
    • cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.6:*:*:*:*:*:*:*
  • Range: <8.7 Patch 1 and <8.8.7
  • Zimbra/ZCSllm-fuzzy
    Range: <8.7 Patch 1 and <8.8.7

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.