Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-03-27T16:00:00
Updated: 2024-08-05T06:17:16.957Z
Reserved: 2018-02-09T00:00:00
Link: CVE-2018-6882
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-03-27T16:29:00.530
Modified: 2024-11-21T04:11:21.710
Link: CVE-2018-6882
Redhat
No data.