lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <03aa8196-1670-9ce6-08de-c8c5f295c9ce@securify.nl> Date: Sat, 24 Mar 2018 12:51:45 +0100 From: "Securify B.V. via Fulldisclosure" <fulldisclosure@...lists.org> To: fulldisclosure@...lists.org Subject: [FD] Cross-Site Scripting vulnerability in Zimbra Collaboration Suite due to the way it handles attachment links ------------------------------------------------------------------------ Cross-Site Scripting vulnerability in Zimbra Collaboration Suite due to the way it handles attachment links ------------------------------------------------------------------------ Stephan Kaag, January 2018 ------------------------------------------------------------------------ Abstract ------------------------------------------------------------------------ A Cross-Site Scripting (XSS) vulnerability was found in Zimbra Collaboration Suite (ZCS). This issue allows an attacker to perform a wide variety of actions such as performing arbitrary actions on their behalf or presenting a fake login screen to collect usernames and passwords. In order to exploit this issue, the attacker has to lure a victim into opening a specially crafted email in ZCS. ------------------------------------------------------------------------ See also ------------------------------------------------------------------------ - CVE-2018-6882 - https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.7 - https://bugzilla.zimbra.com/show_bug.cgi?id=108786 - https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories ------------------------------------------------------------------------ Tested versions ------------------------------------------------------------------------ This issue was successfully tested on ZCS 8.7.11_GA_1854 (build 20170531151956). It is however likely that this issue is present in all versions of ZCS from version 8.5.0 on. ------------------------------------------------------------------------ Fix ------------------------------------------------------------------------ The issue is fixed in Zimbra Collaboration Suite version 8.8.7. ------------------------------------------------------------------------ Details ------------------------------------------------------------------------ https://www.securify.nl/advisory/SFY20180101/cross-site-scripting-vulnerability-in-zimbra-collaboration-suite-due-to-the-way-it-handles-attachment-links.html _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Powered by blists - more mailing lists