CVE-2024-9665
Zimbra
CVE-2024-9665: A Zimbra GraphQL Cross-Site Request Forgery (CSRF) vulnerability allows remote attackers to disclose sensitive information. This flaw affects Zimbra installations, potentially exposing data within target email accounts. The vulnerability arises from inadequate CSRF protections in the graphql endpoint.
Attackers can exploit this by tricking users into opening malicious email messages, initiating requests that reveal sensitive information within the user's account. The SVRS score of 30 indicates a lower risk level compared to critical vulnerabilities, but the presence of the 'In The Wild' tag means active exploitation might be occuring. Despite a moderate CVSS score of 6.5, organizations using Zimbra should still patch promptly to prevent unauthorized information disclosure and potential account compromise. Ignoring this vulnerability can lead to data breaches and compromised user privacy.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.