CVE-2017-8802 Zimbra Collaboration Suite - Stored Cross-Site Scripting

Advisories <[email protected]> Thu, 11 Jan 2018 16:58:51 +0000
Newsgroups gmane.comp.security.bugtraq,gmane.comp.security.news.securitytracker
Message-ID <[email protected]>
###########################################################################=
#########################
#
# COMPASS SECURITY ADVISORY https://www.compass-security.com
###########################################################################=
#########################
#
# CVE ID : CVE-2017-8802
# Product: Zimbra Collaboration Suite (ZCS) [1]
# Vendor:  Synacor Inc. [2]
# Subject: Stored Cross-Site Scripting (XSS) Vulnerability
# Risk:    High
# Effect:  Exploitable by Anonymous Internet Adversaries
#          Triggered in the Context of an Authenticated Zimbra Email User
# Authors: Damian Pfammatter ([email protected])
#          Alessandro Zala   ([email protected])
# Date:    January 10th 2018
#
###########################################################################=
#########################


Introduction:
-------------
The Zimbra Collaboration Suite (ZCS) is a collaborative software suite that=
 includes Email servers
as well as Email clients. According to the product website, more than 500 m=
illion people are
currently using the Email collaboration tool [1].

Security Analysts of Compass Security Schweiz AG [3] discovered a Stored Cr=
oss-Site Scripting (XSS)
vulnerability in the Zimbra Email web client, potentially resulting in a nu=
mber of different attack
scenarios.


Affected Versions:
------------------
No confirmed information about all affected versions is available. Versions=
 prior to 8.8 GA Release
are likely affected.


Technical Description:
----------------------
The Zimbra Email web client is affected by a Stored Cross-Site Scripting (X=
SS) vulnerability.

Remote attackers can target the vulnerability by sending an Email with XSS =
payload (e.g. JavaScript)
in its body. In case the recipient selects the email in the Zimbra client, =
and accesses the "Show
Snippet" functionality using the "Q" shortcut, the XSS payload is executed =
in the context of the
recipient's Zimbra client.

For example through social engineering, attackers could bring their victims=
 into pressing "Q" while
reading the compromised email, triggering the payload. Beside others, the m=
alicious payload could
compromise the confidentility, integrity as well as availability of the vic=
tim's emails. Also it
could be possible to change Zimbra settings of the corresponding victim.


Hotfix:
-------
The corresponding patch has been released in version 8.8.0 Beta2 [4] (Bug #=
107925). The patch is
part of public release 8.8 GA Release.


Timeline:
---------
2017-05-04: Vulnerability discovered
2017-05-05: Initial vendor notification
2017-05-05: Vendor confirmed security issue
2017-05-05: MITRE reserved CVE-2017-8802 for the issue
2017-12-12: Vendor released security fix & guidance to its customers
2018-01-10: Public disclosure


References:
-----------
[1] https://www.zimbra.com/
[2] https://www.synacor.com/
[3] https://www.compass-security.com/research/advisories/
[4] https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories