PT-2017-8386 · Zimbra · Zimbra Collaboration

Publicado

2017-01-18

·

Atualizado

2020-06-04

·

CVE-2016-3406

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration versions prior to 8.7.0
Description The issue involves multiple cross-site request forgery (CSRF) vulnerabilities that allow remote attackers to hijack the authentication of victims. This is achieved through vectors involving the Client uploader extension or extension REST handlers.
Recommendations For versions prior to 8.7.0, update to version 8.7.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Client uploader extension and extension REST handlers to minimize the risk of exploitation.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-3406

Produtos afetados

Zimbra Collaboration