在 Zimbra Collaboration(ZCS)10.1.17 版本之前,Zimbra Collaboration(ZCS)的 Exchange Web Services(EWS)端点存在跨站请求伪造(CSRF)漏洞,该漏洞是由于对请求内容类型验证不足所致。攻击者可以通过诱导已认证用户提交构造的请求来利用此漏洞,从而可能在受害者不知情的情况下执行未授权操作。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Zimbra | Collaboration | < 10.1.17 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zimbra | Collaboration | 0 ~ 10.1.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73570 | 8.9 HIGH | Zimbra Collaboration 命令注入漏洞 |
| CVE-2026-73576 | 6.3 MEDIUM | Zimbra <10.1.17 OnlyOffice弱密钥生成致JWT伪造 |
| CVE-2026-73572 | 6.1 MEDIUM | Zimbra <10.1.17 存储型XSS漏洞 |
| CVE-2026-73573 | 3.1 LOW | Zimbra Collaboration <10.1.17 路径穿越漏洞 |
| CVE-2026-73571 | 3.1 LOW | Zimbra Collaboration <10.1.17 授权绕过漏洞 |
| CVE-2026-73574 | 3.1 LOW | Zimbra<10.1.17经典Web客户端LFI漏洞 |
No comments yet