3.5
CVSSv2

CVE-2017-8802

Published: 16/01/2018 Updated: 09/10/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (aka ZCS) prior to 8.8.0 Beta2 might allow remote malicious users to inject arbitrary web script or HTML via vectors related to the "Show Snippet" functionality.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

synocor zimbra collaboration suite 8.8.0

synocor zimbra collaboration suite

Exploits

Zimbra Collaboration Suite suffers from a stored cross site scripting vulnerability ...

Github Repositories

Security hotfix for CVE-2017-8802

CVE-2017-8802 This Zimlet fixes CVE-2017-8802 by disabling the "Show Fragment" / Snippet functionality For further information see: wikizimbracom/wiki/Zimbra_Security_Advisories How to deploy Zimlets wwwzimbracom/docs/os/6010/administration_guide/Zimlets114html