CVE-2015-7610: CSRF
Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hijack the authentication of unspecified victims by leveraging failure to use a CSRF token.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this security vulnerability?
The vulnerability ID is CVE-2015-7610.
What is the severity of CVE-2015-7610?
The severity of CVE-2015-7610 is high with a severity value of 8.8.
Which versions of Zimbra Collaboration Suite are affected by CVE-2015-7610?
Zimbra Collaboration Suite versions 8.6.0, 8.7.0 to 8.7.11, and 8.8.0 to 8.8.8 are affected by CVE-2015-7610.
How can remote attackers exploit CVE-2015-7610?
Remote attackers can exploit CVE-2015-7610 by leveraging failure to use a CSRF token in the login form to hijack the authentication of victims.
Where can I find more information about CVE-2015-7610 and patches?
You can find more information about CVE-2015-7610 and patches in the Zimbra Security Center and relevant blog posts on the Zimbra website.