Vulnerability Description
Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Synacor | Zimbra Collaboration Suite | >= 8.7.0, <= 8.7.11 |
| Zimbra | Zimbra Collaboration Suite | 8.8.8 |
Related Weaknesses (CWE)
References
- https://blog.zimbra.com/2018/05/new-zimbra-patches-8-8-8-patch-4-and-8-7-11-patcPatchVendor Advisory
- https://wiki.zimbra.com/wiki/Security_CenterPatchVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.7.11/P4PatchRelease NotesVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.8/P4PatchRelease NotesVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_AdvisoriesPatchVendor Advisory
- https://blog.zimbra.com/2018/05/new-zimbra-patches-8-8-8-patch-4-and-8-7-11-patcPatchVendor Advisory
- https://wiki.zimbra.com/wiki/Security_CenterPatchVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.7.11/P4PatchRelease NotesVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.8/P4PatchRelease NotesVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_AdvisoriesPatchVendor Advisory
FAQ
What is CVE-2018-10939?
CVE-2018-10939 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group.
How severe is CVE-2018-10939?
CVE-2018-10939 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10939?
Check the references section above for vendor advisories and patch information. Affected products include: Synacor Zimbra Collaboration Suite, Zimbra Zimbra Collaboration Suite.