8.8
CVSSv3

CVE-2015-6541

Published: 08/04/2016 Updated: 11/04/2016
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) prior to 8.5 allow remote malicious users to hijack the authentication of arbitrary users for requests that change account preferences via a SOAP request to service/soap/BatchRequest.

Vulnerable Product Search on Vulmon Subscribe to Product

zimbra zimbra collaboration server

Exploits

====================================== Multiple CSRF in Zimbra Mail interface ====================================== CVE-2015-6541 Description =========== Multiple CSRF vulnerabilities have been found in the Mail interface of Zimbra 809 GA Release, enabling to change account preferences like e-mail forwarding CSRF ==== Forms in the prefer ...
Zimbra versions 809 GA and below suffer from a cross site request forgery vulnerability ...