{"id":"CVE-2018-6882","title":"Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTM…","summary":"Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTM…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79","CWE-79"],"vendor":"synacor","product":"zimbra_collaboration_suite","affected":["zimbra_collaboration_suite < 8.7.0","zimbra_collaboration_suite = 8.7.0","zimbra_collaboration_suite = 8.8.0","zimbra_collaboration_suite = 8.8.1","zimbra_collaboration_suite = 8.8.2","zimbra_collaboration_suite = 8.8.3","zimbra_collaboration_suite = 8.8.4","zimbra_collaboration_suite = 8.8.5","zimbra_collaboration_suite = 8.8.6"],"patched":["zimbra_collaboration_suite 8.7.0"],"published":"2018-03-27","updated":"2026-08-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2018-6882","references":[{"url":"http://seclists.org/fulldisclosure/2018/Mar/52","label":"cve@mitre.org"},{"url":"http://www.securityfocus.com/archive/1/541891/100/0/threaded","label":"cve@mitre.org"},{"url":"https://bugzilla.zimbra.com/show_bug.cgi?id=108786","label":"cve@mitre.org"},{"url":"https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.7","label":"cve@mitre.org"},{"url":"https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories","label":"cve@mitre.org"},{"url":"https://www.securify.nl/advisory/SFY20180101/cross-site-scripting-vulnerability-in-zimbra-collaboration-suite-due-to-the-way-it-handles-attachment-links.html","label":"cve@mitre.org"},{"url":"http://seclists.org/fulldisclosure/2018/Mar/52","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/archive/1/541891/100/0/threaded","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.zimbra.com/show_bug.cgi?id=108786","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.7","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.securify.nl/advisory/SFY20180101/cross-site-scripting-vulnerability-in-zimbra-collaboration-suite-due-to-the-way-it-handles-attachment-links.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-6882","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.25268,"epssPercentile":0.97891,"kev":true,"kevDateAdded":"2022-04-19","kevDueDate":"2022-05-10","kevRansomware":true,"exploited":true,"ingestedAt":"2026-08-13T06:00:54.224Z","exploits":{"nuclei":["CVE-2018-6882"],"checkedAt":"2026-09-21T15:23:38.342Z"},"exploitAvailable":true,"slug":"CVE-2018-6882","body":"## Overview\n\nCross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.\n\n## Affected\n\n- `zimbra_collaboration_suite < 8.7.0`\n- `zimbra_collaboration_suite = 8.7.0`\n- `zimbra_collaboration_suite = 8.8.0`\n- `zimbra_collaboration_suite = 8.8.1`\n- `zimbra_collaboration_suite = 8.8.2`\n- `zimbra_collaboration_suite = 8.8.3`\n- `zimbra_collaboration_suite = 8.8.4`\n- `zimbra_collaboration_suite = 8.8.5`\n- `zimbra_collaboration_suite = 8.8.6`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `zimbra_collaboration_suite 8.7.0`","depth":"midnight","depthScore":69,"depthScoreParts":{"impact":33.6,"likelihood":5.1,"exploitation":25,"ransomware":5},"changes":[{"seq":4447,"id":"CVE-2018-6882","ts":1788887180687,"field":"exploit_available","old":"false","new":"true"},{"seq":3330,"id":"CVE-2018-6882","ts":1788886299671,"field":"exploit_available","old":"true","new":"false"},{"seq":2185,"id":"CVE-2018-6882","ts":1788882969388,"field":"exploit_available","old":"false","new":"true"},{"seq":1214,"id":"CVE-2018-6882","ts":1788882373812,"field":"exploit_available","old":"true","new":"false"},{"seq":328,"id":"CVE-2018-6882","ts":1788881815692,"field":"exploit_available","old":"false","new":"true"}]}