PT-2017-8386 · Zimbra · Zimbra Collaboration

Published

2017-01-18

·

Updated

2020-06-04

·

CVE-2016-3406

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration versions prior to 8.7.0
Description The issue involves multiple cross-site request forgery (CSRF) vulnerabilities that allow remote attackers to hijack the authentication of victims. This is achieved through vectors involving the Client uploader extension or extension REST handlers.
Recommendations For versions prior to 8.7.0, update to version 8.7.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Client uploader extension and extension REST handlers to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-3406

Affected Products

Zimbra Collaboration