Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account. This differs from the intended behavior in which the domain of the authenticated user must match the domain of the galsync account in the request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Zimbra zm-mailbox 安全漏洞
Vulnerability Description
Zimbra zm-mailbox是美国Zimbra公司的一款邮箱管理工具。 Zimbra zm-mailbox 8.8.15.p8之前版本中的cs/service/account/AutoCompleteGal.java文件存在安全漏洞。攻击者可利用该漏洞请求任意GAL账户。
CVSS Information
N/A
Vulnerability Type
N/A