← Vulnerability feed

Vulnerability record · CVE-2018-6882 · published 27 March 2018

CVE-2018-6882: Zimbra Collaboration Suite XSS via attachment Content-Location header

SSynacor · Zimbra Collaboration Suite

Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 fails to properly sanitize the Content-Location header of an email attachment in ZmMailMsgView.getAttachmentLinkHtml, allowing arbitrary web script or HTML injection. Because the flaw lives in the webmail attachment rendering path, a crafted email can execute script in the victim's authenticated Zimbra session.

6.1 CVSS 3.1 Medium CISA KEV since 19 Apr 2022 Known ransomware use EPSS 30% · top 1.9% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
30%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
13References, 2 tagged exploit
13 Aug 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityAlthough CVSS is medium (6.1), the vulnerability is in CISA KEV with known ransomware use and high EPSS, indicating active exploitation and elevated risk for unpatched Zimbra deployments.

What it is

Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 fails to properly sanitize the Content-Location header of an email attachment in ZmMailMsgView.getAttachmentLinkHtml, allowing arbitrary web script or HTML injection. Because the flaw lives in the webmail attachment rendering path, a crafted email can execute script in the victim's authenticated Zimbra session.

Impact

An attacker can run arbitrary script in the context of the victim's Zimbra webmail session, enabling session theft, mailbox data exfiltration, or actions performed as the victim. The CVSS scope change (S:C) reflects that the injected script can affect resources beyond the vulnerable component.

Attack surface

Reached remotely over the network by sending an email with a malicious Content-Location header in an attachment; the victim must open or view the attachment in Zimbra webmail, so user interaction is required and no prior authentication on the attacker's side is needed.

Exploitation

CVE-2018-6882 is listed in CISA KEV (added 2022-04-19) with known ransomware campaign use, and EPSS shows a 30-day probability of 0.25268 (97.8th percentile); a public exploit reference is tagged in the advisory. This indicates active exploitation in the wild, not just theoretical risk.

What to do

  • Upgrade Zimbra Collaboration Suite to 8.7 Patch 1 or 8.8.7 (or later) as directed by the vendor advisory.
  • If immediate patching is not possible, restrict or disable webmail attachment preview/rendering for untrusted senders.
  • Enforce email filtering to strip or quarantine messages with suspicious Content-Location headers in attachments.
  • Apply the vendor security advisory guidance and monitor for follow-up Zimbra security releases.
  • Segment and harden Zimbra webmail exposure (limit internet-facing access, enforce MFA) to reduce session theft impact.

Detection

  • Search Zimbra webmail/proxy logs for requests or responses containing Content-Location headers with script-like or HTML payloads in attachment handling.
  • Monitor for anomalous JavaScript execution or outbound requests originating from Zimbra webmail sessions (e.g., unusual referrers or callback domains).
  • Alert on emails with attachments whose Content-Location header contains angle brackets, script tags, or encoded HTML entities.
  • Review Zimbra server and client-side logs for attachment view events correlated with known malicious sender domains or IOCs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-6882 to the Known Exploited Vulnerabilities catalog on 19 April 2022 as "Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 10 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-6882 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-45519Zimbra Collaboration postjournal service unauthenticated command executionThe postjournal service in Zimbra Collaboration Suite fails to properly neutralize input, allowing OS command injection. Because the service can be r…KEVEPSS 100%analysed9.8CVE-2022-41352Zimbra Collaboration amavis cpio path traversal arbitrary file uploadZimbra Collaboration Suite 8.8.15 and 9.0 allow an attacker to upload arbitrary files through amavis by abusing cpio archive extraction into the web-…KEVEPSS 95%analysed9.8CVE-2022-37042Zimbra Collaboration Suite mboximport auth bypass path traversal RCEZimbra Collaboration Suite 8.8.15 and 9.0 mboximport accepts a ZIP archive and extracts files without requiring an authtoken, allowing unauthenticate…KEVEPSS 92%analysed9.8CVE-2020-7796Zimbra Collaboration Suite WebEx zimlet SSRFZimbra Collaboration Suite before 8.8.15 Patch 7 is vulnerable to server-side request forgery when the WebEx zimlet is installed and its JSP is enabl…KEVEPSS 84%analysed9.8CVE-2019-9670Zimbra mailboxd Autodiscover XXE allows unauthenticated compromiseThe mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 parses XML in the Autodiscover servlet without restricting extern…KEVEPSS 100%analysed9.0CVE-2023-34192Zimbra ZCS autoSaveDraft XSS enables remote code executionZimbra Collaboration Suite 8.8.15 has a cross-site scripting flaw in the /h/autoSaveDraft function. A remote authenticated attacker can inject a craf…KEVEPSS 77%analysed8.9CVE-2026-73570Zimbra Collaboration SNMP notification OS command injectionZimbra Collaboration Suite before 10.1.20 contains an OS command injection flaw in SNMP notification processing when the optional zimbra-snmp package…KEVEPSS 12%analysed8.8CVE-2025-68645Zimbra Webmail Classic UI RestFilter local file inclusionZimbra Collaboration Suite 10.0 and 10.1 mishandle user-supplied parameters in the RestFilter servlet of the Webmail Classic UI, allowing local file …KEVEPSS 49%analysed

Source: NIST National Vulnerability Database (record CVE-2018-6882), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.