CVE-2024-45518

An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. It allows authenticated users to exploit Server-Side Request Forgery (SSRF) due to improper input sanitization and misconfigured domain whitelisting. This issue permits unauthorized HTTP requests to be sent to internal services, which can lead to Remote Code Execution (RCE) by chaining Command Injection within the internal service. When combined with existing XSS vulnerabilities, this SSRF issue can further facilitate Remote Code Execution (RCE).
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CISA-ADPADP
7.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
zimbracollaboration
10.0.0 ≤
𝑥
< 10.0.9
zimbracollaboration
8.8.15
zimbracollaboration
8.8.15:p1
zimbracollaboration
8.8.15:p10
zimbracollaboration
8.8.15:p11
zimbracollaboration
8.8.15:p12
zimbracollaboration
8.8.15:p13
zimbracollaboration
8.8.15:p14
zimbracollaboration
8.8.15:p15
zimbracollaboration
8.8.15:p16
zimbracollaboration
8.8.15:p17
zimbracollaboration
8.8.15:p18
zimbracollaboration
8.8.15:p19
zimbracollaboration
8.8.15:p2
zimbracollaboration
8.8.15:p20
zimbracollaboration
8.8.15:p21
zimbracollaboration
8.8.15:p22
zimbracollaboration
8.8.15:p23
zimbracollaboration
8.8.15:p24
zimbracollaboration
8.8.15:p25
zimbracollaboration
8.8.15:p26
zimbracollaboration
8.8.15:p27
zimbracollaboration
8.8.15:p28
zimbracollaboration
8.8.15:p29
zimbracollaboration
8.8.15:p3
zimbracollaboration
8.8.15:p30
zimbracollaboration
8.8.15:p31
zimbracollaboration
8.8.15:p32
zimbracollaboration
8.8.15:p33
zimbracollaboration
8.8.15:p34
zimbracollaboration
8.8.15:p35
zimbracollaboration
8.8.15:p37
zimbracollaboration
8.8.15:p4
zimbracollaboration
8.8.15:p40
zimbracollaboration
8.8.15:p41
zimbracollaboration
8.8.15:p42
zimbracollaboration
8.8.15:p43
zimbracollaboration
8.8.15:p44
zimbracollaboration
8.8.15:p45
zimbracollaboration
8.8.15:p5
zimbracollaboration
8.8.15:p6
zimbracollaboration
8.8.15:p7
zimbracollaboration
8.8.15:p8
zimbracollaboration
8.8.15:p9
zimbracollaboration
9.0.0
zimbracollaboration
9.0.0:p0
zimbracollaboration
9.0.0:p1
zimbracollaboration
9.0.0:p10
zimbracollaboration
9.0.0:p11
zimbracollaboration
9.0.0:p12
zimbracollaboration
9.0.0:p13
zimbracollaboration
9.0.0:p14
zimbracollaboration
9.0.0:p15
zimbracollaboration
9.0.0:p16
zimbracollaboration
9.0.0:p19
zimbracollaboration
9.0.0:p2
zimbracollaboration
9.0.0:p20
zimbracollaboration
9.0.0:p21
zimbracollaboration
9.0.0:p23
zimbracollaboration
9.0.0:p24
zimbracollaboration
9.0.0:p24.1
zimbracollaboration
9.0.0:p25
zimbracollaboration
9.0.0:p26
zimbracollaboration
9.0.0:p27
zimbracollaboration
9.0.0:p3
zimbracollaboration
9.0.0:p33
zimbracollaboration
9.0.0:p34
zimbracollaboration
9.0.0:p35
zimbracollaboration
9.0.0:p36
zimbracollaboration
9.0.0:p37
zimbracollaboration
9.0.0:p38
zimbracollaboration
9.0.0:p39
zimbracollaboration
9.0.0:p4
zimbracollaboration
9.0.0:p40
zimbracollaboration
9.0.0:p5
zimbracollaboration
9.0.0:p6
zimbracollaboration
9.0.0:p7
zimbracollaboration
9.0.0:p7.1
zimbracollaboration
9.0.0:p8
zimbracollaboration
9.0.0:p9
zimbracollaboration
10.1.0
𝑥
= Vulnerable software versions