Description
Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
None
Affected products
- Zimbra / Collaboration0 – 10.1.12
References
- VENDOR_ADVISORYhttps://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- MISChttps://wiki.zimbra.com/wiki/Security_Center
- MISChttps://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.12
- MISChttps://blog.zimbra.com/2025/10/patch-release-update-zimbra-10-1-12/
- MISChttps://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.12#Security_Fixes
Updated 21m ago · 8 sources