Intrusion Prevention

Zimbra.Email.Body.XSS

Description

This indicates an attack attempt against a persistent Cross-Site Scripting (XSS) vulnerability in Zimbra Collaboration.
The vulnerability is caused due to insufficientl sanitizing of email body content. It allows remote attackers to launch XSS attack against Zimbra Collaboration users.

Affected Products

Zimbra Collaboration 8.6.0 Patch4 and before

Impact

System Compromise: Remote attackers can execute arbitrary script code in the context of the affected user.

Recommended Actions

Apply the vendor's patch which is available at
https://community.zimbra.com/collaboration/f/1884/t/1140919

CVE References

CVE-2015-7609