Multiple cross-site request forgery (CSRF) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to hijack the authentication of unspecified victims via vectors involving (1) the Client uploader extension or (2) extension REST handlers, aka bugs 104294 and 104456.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-01-18T22:00:00
Updated: 2024-08-05T23:56:13.406Z
Reserved: 2016-03-17T00:00:00
Link: CVE-2016-3406
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-01-18T22:59:00.343
Modified: 2024-11-21T02:49:56.303
Link: CVE-2016-3406
Redhat
No data.