PT-2025-38161 · Zimbra · Zimbra Collaboration

Published

2025-09-17

·

Updated

2025-09-19

·

CVE-2025-54390

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration (affected versions not specified)
Description A Cross-Site Request Forgery (CSRF) vulnerability exists in the ResetPasswordRequest operation of Zimbra Collaboration (ZCS) when the zimbraFeatureResetPasswordStatus attribute is enabled. An attacker can exploit this by tricking an authenticated user into visiting a malicious webpage that silently sends a crafted SOAP request to reset the user's password. The vulnerability stems from a lack of CSRF token validation on the endpoint, allowing password resets without the user's consent.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-54390

Affected Products

Zimbra Collaboration