Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hijack the authentication of unspecified victims by leveraging failure to use a CSRF token.
| Software | From | Fixed in |
|---|---|---|
| zimbra / zimbra_collaboration_suite | 8.6.0-p1 | 8.6.0-p1.x |
| zimbra / zimbra_collaboration_suite | 8.6.0-p2 | 8.6.0-p2.x |
| zimbra / zimbra_collaboration_suite | 8.6.0-p3 | 8.6.0-p3.x |
| zimbra / zimbra_collaboration_suite | 8.6.0-p4 | 8.6.0-p4.x |
| zimbra / zimbra_collaboration_suite | 8.6.0-p5 | 8.6.0-p5.x |
| zimbra / zimbra_collaboration_suite | 8.6.0-p6 | 8.6.0-p6.x |
| zimbra / zimbra_collaboration_suite | 8.6.0-p7 | 8.6.0-p7.x |
| zimbra / zimbra_collaboration_suite | 8.6.0-p8 | 8.6.0-p8.x |
| zimbra / zimbra_collaboration_suite | 8.6.0-p9 | 8.6.0-p9.x |
| synacor / zimbra_collaboration_suite | 8.7.11-p1 | 8.7.11-p1.x |
| synacor / zimbra_collaboration_suite | 8.6.0 | 8.6.0.x |
| synacor / zimbra_collaboration_suite | 8.7.0 | 8.7.11.x |
| synacor / zimbra_collaboration_suite | 8.8.0 | 8.8.8.x |