{"id":"CVE-2018-14425","details":"There is a Persistent XSS vulnerability in the briefcase component of Synacor Zimbra Collaboration Suite (ZCS) Zimbra Web Client (ZWC) 8.8.8 before 8.8.8 Patch 7 and 8.8.9 before 8.8.9 Patch 1.","modified":"2026-09-14T08:12:49.227061Z","published":"2019-05-30T18:29:02.597Z","references":[{"type":"ADVISORY","url":"https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories"},{"type":"REPORT","url":"https://bugzilla.zimbra.com/show_bug.cgi?id=108970"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-build","events":[{"introduced":"0"},{"fixed":"a12f6b5f02776dff1d0554a7998ae6c6ee0dd820"},{"introduced":"a12f6b5f02776dff1d0554a7998ae6c6ee0dd820"},{"last_affected":"5000d7ff7c8650dbfff91678647fabc2bbf0e64b"}],"database_specific":{"cpe":["cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*","cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.8:-:*:*:*:*:*:*","cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.8:patch1:*:*:*:*:*:*","cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.8:patch3:*:*:*:*:*:*","cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.8:patch4:*:*:*:*:*:*","cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.9:-:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"8.8.8"},{"introduced":"8.8.8-NA"},{"last_affected":"8.8.8-NA"},{"introduced":"8.8.8-patch1"},{"last_affected":"8.8.8-patch1"},{"introduced":"8.8.8-patch3"},{"last_affected":"8.8.8-patch3"},{"introduced":"8.8.8-patch4"},{"last_affected":"8.8.8-patch4"},{"introduced":"8.8.9-NA"},{"last_affected":"8.8.9-NA"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["8.8.8-NA","8.8.8-patch1","8.8.9-NA","8.8.9.p3","8.8.9.p1","8.8.9","8.8.8","8.7.11","8.8.7","8.8.6","8.8.4","8.8.3","8.8.2","8.8.0.beta1","8.7.10","8.7.9","8.7.7","8.7.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-14425.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-mailbox","events":[{"introduced":"0"},{"fixed":"49778e9798e139cb059be07aa1810a2d624ef888"},{"introduced":"49778e9798e139cb059be07aa1810a2d624ef888"},{"last_affected":"d5dcfa4470bbb057d961a28fc9c35717eeaa7225"}],"database_specific":{"cpe":["cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*","cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.8:-:*:*:*:*:*:*","cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.8:patch1:*:*:*:*:*:*","cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.8:patch3:*:*:*:*:*:*","cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.8:patch4:*:*:*:*:*:*","cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.9:-:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"8.8.8"},{"introduced":"8.8.8-NA"},{"last_affected":"8.8.8-NA"},{"introduced":"8.8.8-patch1"},{"last_affected":"8.8.8-patch1"},{"introduced":"8.8.8-patch3"},{"last_affected":"8.8.8-patch3"},{"introduced":"8.8.8-patch4"},{"last_affected":"8.8.8-patch4"},{"introduced":"8.8.9-NA"},{"last_affected":"8.8.9-NA"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["8.8.8-NA","8.8.8-patch1","8.8.8-patch3","8.8.8-patch4","8.8.9-NA","8.8.8","8.8.9","8.8.7","8.8.6","8.8.5","8.8.4","8.8.3","8.8.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-14425.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-zcs","events":[{"introduced":"0"},{"fixed":"34aff8ccf0b1b56d129015c54153bf823915f8ce"},{"introduced":"34aff8ccf0b1b56d129015c54153bf823915f8ce"},{"last_affected":"d36a4c8999c6377b7ae36c22f47bbea75974e8cc"}],"database_specific":{"cpe":["cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*","cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.8:-:*:*:*:*:*:*","cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.9:-:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"8.8.8"},{"introduced":"8.8.8-NA"},{"last_affected":"8.8.8-NA"},{"introduced":"8.8.9-NA"},{"last_affected":"8.8.9-NA"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["8.8.8-NA","8.8.9-NA","8.8.9","8.8.8","8.7.11","8.8.7","8.8.6","8.8.5","8.8.4","8.8.3","8.8.2","8.8.0beta2","8.8.0.beta1","8.7.10","8.7.9","8.7.7","8.7.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-14425.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-zcs-lib","events":[{"introduced":"0"},{"fixed":"048ff3fb24f199ee7081e4f1504ec965cdc98be6"},{"introduced":"048ff3fb24f199ee7081e4f1504ec965cdc98be6"},{"last_affected":"6e5ea502a8b78a16e1c2d1d51331b62c31eb4c7e"}],"database_specific":{"cpe":["cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*","cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.8:-:*:*:*:*:*:*","cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.9:-:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"8.8.8"},{"introduced":"8.8.8-NA"},{"last_affected":"8.8.8-NA"},{"introduced":"8.8.9-NA"},{"last_affected":"8.8.9-NA"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["8.8.8-NA","8.8.9-NA","8.8.9","8.8.8","8.7.11","8.8.7","8.8.6","8.8.5","8.8.4","8.8.3","8.8.2","8.8.0.beta1","8.7.10","8.7.9","8.7.7","8.7.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-14425.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}