{"id":"CVE-2018-6882","aliases":[],"url":"https://o3.security/vulnerability/CVE-2018-6882","summary":null,"details":"Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.","published":"2018-03-27T16:29:00.530Z","modified":"2026-09-06T03:45:08.851690320Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.2542,"percentile":0.97781,"asOf":"2026-08-24"},"cisaKev":{"dateAdded":"2022-04-19","dueDate":"2022-05-10","knownRansomwareCampaignUse":true},"exploitsKnown":4,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-6882"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2018/Mar/52"},{"type":"ADVISORY","url":"http://www.securityfocus.com/archive/1/541891/100/0/threaded"},{"type":"ADVISORY","url":"https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories"},{"type":"REPORT","url":"https://bugzilla.zimbra.com/show_bug.cgi?id=108786"},{"type":"REPORT","url":"https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.7"},{"type":"EVIDENCE","url":"https://www.securify.nl/advisory/SFY20180101/cross-site-scripting-vulnerability-in-zimbra-collaboration-suite-due-to-the-way-it-handles-attachment-links.html"}],"provenance":{"sources":["OSV.dev","CISA KEV","FIRST.org (EPSS)"],"lastVerified":"2026-09-06T03:45:08.851690320Z"}}