VYPR
High severity8.8NVD Advisory· Published May 30, 2018· Updated Jun 17, 2026

CVE-2015-7610

CVE-2015-7610

Description

Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hijack the authentication of unspecified victims by leveraging failure to use a CSRF token.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

15
  • Range: <8.6.0 Patch 10 || >=8.7.0,<8.7.11 Patch 2 || >=8.8.0,<8.8.8 Patch 1
  • cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*range: >=8.7.0,<=8.7.11
    • cpe:2.3:a:synacor:zimbra_collaboration_suite:8.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p1:*:*:*:*:*:*
  • cpe:2.3:a:zimbra:zimbra_collaboration_suite:8.6.0:p1:*:*:*:*:*:*+ 8 more
    • cpe:2.3:a:zimbra:zimbra_collaboration_suite:8.6.0:p1:*:*:*:*:*:*
    • cpe:2.3:a:zimbra:zimbra_collaboration_suite:8.6.0:p2:*:*:*:*:*:*
    • cpe:2.3:a:zimbra:zimbra_collaboration_suite:8.6.0:p3:*:*:*:*:*:*
    • cpe:2.3:a:zimbra:zimbra_collaboration_suite:8.6.0:p4:*:*:*:*:*:*
    • cpe:2.3:a:zimbra:zimbra_collaboration_suite:8.6.0:p5:*:*:*:*:*:*
    • cpe:2.3:a:zimbra:zimbra_collaboration_suite:8.6.0:p6:*:*:*:*:*:*
    • cpe:2.3:a:zimbra:zimbra_collaboration_suite:8.6.0:p7:*:*:*:*:*:*
    • cpe:2.3:a:zimbra:zimbra_collaboration_suite:8.6.0:p8:*:*:*:*:*:*
    • cpe:2.3:a:zimbra:zimbra_collaboration_suite:8.6.0:p9:*:*:*:*:*:*
  • Range: <8.6.0 Patch 10, <8.7.11 Patch 2, <8.8.8 Patch 1
  • Zimbra/ZCSllm-fuzzy
    Range: <8.6.0 Patch 10, <8.7.11 Patch 2, <8.8.8 Patch 1

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.