CVE-2015-7610: Synacor Zimbra Collaboration Suite

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hijack the authentication of unspecified victims by leveraging failure to use a CSRF token.

Affected products

  • Synacor Zimbra Collaboration Suite: from 8.7.0, up to and including 8.7.11; from 8.8.0, up to and including 8.8.8; version 8.6.0 only; version 8.7.11 only
  • Zimbra Zimbra Collaboration Suite: version 8.6.0 only

Published 2018-05-30. Last modified 2026-06-17.