Vulnerability record · CVE-2018-6882 · published 27 March 2018
CVE-2018-6882: Zimbra Collaboration Suite XSS via attachment Content-Location header
SSynacor · Zimbra Collaboration Suite
Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 fails to properly sanitize the Content-Location header of an email attachment in ZmMailMsgView.getAttachmentLinkHtml, allowing arbitrary web script or HTML injection. Because the flaw lives in the webmail attachment rendering path, a crafted email can execute script in the victim's authenticated Zimbra session.
Description
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityAlthough CVSS is medium (6.1), the vulnerability is in CISA KEV with known ransomware use and high EPSS, indicating active exploitation and elevated risk for unpatched Zimbra deployments.
What it is
Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 fails to properly sanitize the Content-Location header of an email attachment in ZmMailMsgView.getAttachmentLinkHtml, allowing arbitrary web script or HTML injection. Because the flaw lives in the webmail attachment rendering path, a crafted email can execute script in the victim's authenticated Zimbra session.
Impact
An attacker can run arbitrary script in the context of the victim's Zimbra webmail session, enabling session theft, mailbox data exfiltration, or actions performed as the victim. The CVSS scope change (S:C) reflects that the injected script can affect resources beyond the vulnerable component.
Attack surface
Reached remotely over the network by sending an email with a malicious Content-Location header in an attachment; the victim must open or view the attachment in Zimbra webmail, so user interaction is required and no prior authentication on the attacker's side is needed.
Exploitation
CVE-2018-6882 is listed in CISA KEV (added 2022-04-19) with known ransomware campaign use, and EPSS shows a 30-day probability of 0.25268 (97.8th percentile); a public exploit reference is tagged in the advisory. This indicates active exploitation in the wild, not just theoretical risk.
What to do
- Upgrade Zimbra Collaboration Suite to 8.7 Patch 1 or 8.8.7 (or later) as directed by the vendor advisory.
- If immediate patching is not possible, restrict or disable webmail attachment preview/rendering for untrusted senders.
- Enforce email filtering to strip or quarantine messages with suspicious Content-Location headers in attachments.
- Apply the vendor security advisory guidance and monitor for follow-up Zimbra security releases.
- Segment and harden Zimbra webmail exposure (limit internet-facing access, enforce MFA) to reduce session theft impact.
Detection
- Search Zimbra webmail/proxy logs for requests or responses containing Content-Location headers with script-like or HTML payloads in attachment handling.
- Monitor for anomalous JavaScript execution or outbound requests originating from Zimbra webmail sessions (e.g., unusual referrers or callback domains).
- Alert on emails with attachments whose Content-Location header contains angle brackets, script tags, or encoded HTML entities.
- Review Zimbra server and client-side logs for attachment view events correlated with known malicious sender domains or IOCs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-6882 to the Known Exploited Vulnerabilities catalog on 19 April 2022 as "Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 10 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-6882 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-6882), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.