CVE-2017-8802
Status: ModifiedMedium (5.4)—💥 PoC
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.8.0 Beta2 might allow remote attackers to inject arbitrary web script or HTML via vectors related to the "Show Snippet" functionality.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Base score: 5.4
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.27%
- Percentile among all scored CVEs: 69
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Proof of concept on GitHub (unverified) · List of proofs of concept on GitHub
⚠️ GitHub proofs of concept are not verified: some are fake or contain malware. Never run them outside an isolated lab.
Affected technologies (1)
CWEs
- CWE-79
References
- http://www.securityfocus.com/archive/1/541661/100/0/threaded
- https://bugzilla.zimbra.com/show_bug.cgi?id=107925
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2018-001_zimbra_stored_xss.txt
- http://www.securityfocus.com/archive/1/541661/100/0/threaded
- https://bugzilla.zimbra.com/show_bug.cgi?id=107925
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2018-001_zimbra_stored_xss.txt
Raw JSON (NVD)
Show
{
"id": "CVE-2017-8802",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2018-01-16T19:29:01.480",
"references": [
{
"url": "http://www.securityfocus.com/archive/1/541661/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.zimbra.com/show_bug.cgi?id=107925",
"tags": [
"Permissions Required"
],
"source": "cve@mitre.org"
},
{
"url": "https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2018-001_zimbra_stored_xss.txt",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/541661/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.zimbra.com/show_bug.cgi?id=107925",
"tags": [
"Permissions Required"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2018-001_zimbra_stored_xss.txt",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.8.0 Beta2 might allow remote attackers to inject arbitrary web script or HTML via vectors related to the \"Show Snippet\" functionality."
},
{
"lang": "es",
"value": "Vulnerabilidad de Cross-Site Scripting (XSS) en Zimbra Collaboration Suite (también conocido como ZCS) en versiones anteriores a la 8.8.0 Beta2 puede permitir que los atacantes remotos inyecten scripts web o HTML arbitrarios mediante vectores relacionados con la funcionalidad \"Show Snippet\"."
}
],
"lastModified": "2026-06-17T01:26:59.243",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:synocor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "289718C8-9E62-419A-A882-252CFCB152D4",
"versionEndIncluding": "8.7.11"
},
{
"criteria": "cpe:2.3:a:synocor:zimbra_collaboration_suite:8.8.0:beta1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C23673FA-DC03-4586-A175-690B3328E7B1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}