云虫漏洞库

CVE-2026-73575 - In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by causing an authenticated user to submit a crafted request, potentially allowing unauthorized actions to be performed on behalf of the victim. - 漏洞详情

漏洞编号:CVE-2026-73575

风险等级:低危

漏洞来源:CVE

CVE 编号:CVE-2026-73575

CNNVD 编号:-

厂商/产品:synacor / zimbra_collaboration_suite

影响范围:cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*

CWE:CWE-352

发布/更新时间:2026-08-13 / 2026-08-28

漏洞描述

In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by causing an authenticated user to submit a crafted request, potentially allowing unauthorized actions to be performed on behalf of the victim.

相关链接

相关漏洞

« 返回首页