vendor:
Zimbra Mail Server
by:
Anthony LAOU-HINE TSUEI, Sysdream and Damien CAUQUIL, Sysdream
8,8
CVSS
HIGH
CSRF
352
CWE
Product Name: Zimbra Mail Server
Affected Version From: Zimbra <= 8.0.9 GA Release
Affected Version To: Zimbra <= 8.0.9 GA Release
Patch Exists: YES
Related CWE: CVE-2015-6541
CPE: a:zimbra:zimbra_mail_server:8.0.9
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
Multiple CSRF in Zimbra Mail interface
Multiple CSRF vulnerabilities have been found in the Mail interface of Zimbra 8.0.9 GA Release, enabling to change account preferences like e-mail forwarding. Forms in the preferences part of old releases of Zimbra are vulnerable to CSRF because of the lack of a CSRF token identifying a valid session. As a consequence, requests can be forged and played arbitrarily.
Mitigation:
Sensitive forms should be protected by a CSRF token.