4.3
CVSSv2

CVE-2016-3411

Published: 18/01/2017 Updated: 04/06/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Zimbra Collaboration prior to 8.7.0 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors, aka bug 103609.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

synacor zimbra collaboration suite

Exploits

# Exploit Title: Xss Zimbra Mail server # Google Dork: # Date: 2018/08/10 # Exploit Author: Dinbar78 # Vendor Homepage: wwwzimbracom/ # Version: 860_GA_1153 (build 20141215151110) # bug 103609 or CVE-2016-3411 Payload: es (zimbrasite)/h/changepass?skin="><script>alert('hacked');</script> ...
Zimbra version 860_GA_1153 build 20141215151110 suffers from a cross site scripting vulnerability ...