3.1 LOW
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
Activity log
- Created suggestion
In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery …
In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by causing an authenticated user to submit a crafted request, potentially allowing unauthorized actions to be performed on behalf of the victim.
References
Affected products
- <10.1.17
Matching in nixpkgs
pkgs.lasuite-docs-collaboration-server
Collaborative note taking, wiki and documentation platform that scales. Built with Django and React. Opensource alternative to Notion or Outline
pkgs.python313Packages.jupyter-collaboration
JupyterLab Extension enabling Real-Time Collaboration
pkgs.python314Packages.jupyter-collaboration
JupyterLab Extension enabling Real-Time Collaboration
pkgs.python313Packages.jupyter-collaboration-ui
JupyterLab/Jupyter Notebook 7+ extension providing user interface integration for real time collaboration
Package maintainers
-
@Ma27 Maximilian Bosch <maximilian@mbosch.me>
-
@soyouzpanda soyouzpanda <soyouzpanda@soyouzpanda.fr>
-
@natsukium Tomoya Otabi <nixpkgs@natsukium.com>
-
@thomasjm Tom McLaughlin <tom@codedown.io>
-
@GaetanLepage Gaetan Lepage <gaetan@glepage.com>