First published: Wed May 17 2017(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Zimbra Collaboration before 8.6.0 Patch 8 allow remote attackers to hijack the authentication of administrators for requests that (1) add, (2) modify, or (3) remove accounts by leveraging failure to use of a CSRF token and perform referer header checks, aka bugs 100885 and 100899.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zimbra Collaboration Suite | <=8.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3403 is classified as a medium severity vulnerability due to its potential to allow unauthorized actions by remote attackers.
To fix CVE-2016-3403, upgrade Zimbra Collaboration Suite to version 8.6.0 Patch 8 or later.
CVE-2016-3403 allows remote attackers to perform cross-site request forgery (CSRF) attacks to hijack administrator accounts and manipulate user accounts.
CVE-2016-3403 affects all versions of Zimbra Collaboration Suite prior to 8.6.0 Patch 8.
In the context of CVE-2016-3403, CSRF vulnerabilities can be exploited to send unauthorized commands to the server on behalf of an authenticated administrator.