Cross-Site Request Forgery Vulnerability in Zimbra Collaboration Server Mail Interface
CVE-2015-6541

8.8HIGH

Key Information:

Vendor

Zimbra

Vendor
CVE Published:
8 April 2016

What is CVE-2015-6541?

The Zimbra Collaboration Server (ZCS) contains multiple vulnerabilities in its Mail interface that can be exploited via cross-site request forgery (CSRF) attacks. These vulnerabilities allow remote attackers to hijack user authentication during SOAP requests, enabling unauthorized changes to user account preferences. Users are at risk if using versions prior to 8.5, which do not incorporate necessary security measures to prevent such exploitations. It is crucial for organizations to upgrade their ZCS installations and implement additional security practices to safeguard against these vulnerabilities.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.