← Back

CVE-2018-10939

nvd nist
Published: May 30, 2018Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group.

Affected (8)

1 product
Zimbra Collaboration Suite
1 product
Zimbra Collaboration Suite
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Synacor
From 8.7.0 to 8.7.11
From 8.8.0 to 8.8.8
Version 8.7.11 p1
Version 8.7.11 p2
Version 8.7.11 p3
Version 8.8.8 p1
Version 8.8.8 p3
Version 8.8.8 p2

References (10)

Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchRelease NotesVendor Advisory
Source: cve@mitre.org
PatchRelease NotesVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.