CVE-2015-7610
30.05.2018, 21:29
Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hijack the authentication of unspecified victims by leveraging failure to use a CSRF token.
Vendor | Product | Version |
---|---|---|
synacor | zimbra_collaboration_suite | 8.7.0 ≤ 𝑥 ≤ 8.7.11 |
synacor | zimbra_collaboration_suite | 8.8.0 ≤ 𝑥 ≤ 8.8.8 |
synacor | zimbra_collaboration_suite | 8.6.0 |
synacor | zimbra_collaboration_suite | 8.7.11:p1 |
zimbra | zimbra_collaboration_suite | 8.6.0:p1 |
zimbra | zimbra_collaboration_suite | 8.6.0:p2 |
zimbra | zimbra_collaboration_suite | 8.6.0:p3 |
zimbra | zimbra_collaboration_suite | 8.6.0:p4 |
zimbra | zimbra_collaboration_suite | 8.6.0:p5 |
zimbra | zimbra_collaboration_suite | 8.6.0:p6 |
zimbra | zimbra_collaboration_suite | 8.6.0:p7 |
zimbra | zimbra_collaboration_suite | 8.6.0:p8 |
zimbra | zimbra_collaboration_suite | 8.6.0:p9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References