CVE-2015-7610

Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hijack the authentication of unspecified victims by leveraging failure to use a CSRF token.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
synacorzimbra_collaboration_suite
8.7.0 ≤
𝑥
≤ 8.7.11
synacorzimbra_collaboration_suite
8.8.0 ≤
𝑥
≤ 8.8.8
synacorzimbra_collaboration_suite
8.6.0
synacorzimbra_collaboration_suite
8.7.11:p1
zimbrazimbra_collaboration_suite
8.6.0:p1
zimbrazimbra_collaboration_suite
8.6.0:p2
zimbrazimbra_collaboration_suite
8.6.0:p3
zimbrazimbra_collaboration_suite
8.6.0:p4
zimbrazimbra_collaboration_suite
8.6.0:p5
zimbrazimbra_collaboration_suite
8.6.0:p6
zimbrazimbra_collaboration_suite
8.6.0:p7
zimbrazimbra_collaboration_suite
8.6.0:p8
zimbrazimbra_collaboration_suite
8.6.0:p9
𝑥
= Vulnerable software versions