Impact
A Cross‑Site Request Forgery (CSRF) flaw exists in the Exchange Web Services endpoint of Zimbra Collaboration Service (ZCS) prior to version 10.1.17. The vulnerability stems from insufficient validation of request content types, which allows a malicious actor to entice an authenticated user into submitting a crafted request that the server processes as if it originated from that user. Successful exploitation could therefore lead to the unauthorized execution of privileged actions on the victim's behalf, such as altering account settings or performing other sensitive operations. This weakness aligns with CWE‑352, as it exploits the lack of proper origin verification.
Affected Systems
Products affected are Zimbra Collaboration Service installations running versions earlier than 10.1.17. All ZCS deployments that expose the EWS endpoint to authenticated web sessions are vulnerable, regardless of the hosting environment. The issue is not confined to a specific operating system or deployment type; any customer using ZCS before 10.1.17 is at risk.
Risk and Exploitability
The CVSS score of 3.1 indicates a low severity level, and the absence of an EPSS rating combined with the fact that the vulnerability is not listed in CISA's KEV catalog suggest a modest risk. Exploitation requires the victim to be logged in, to view a malicious page that forces a request to the vulnerable endpoint, and for the request to contain an accepted content type—conditions that limit spontaneous exploitation. While no public exploits are currently available, organizations running outdated ZCS should consider the risk moderate due to the potential impact on privileged user accounts and the relative ease of delivering forged requests via phishing or compromised web pages.
OpenCVE Enrichment