CVE-2024-45518

HIGH

Zimbra Collaboration <10.1.1-8.8.15 - SSRF

Title source: llm
STIX 2.1

Description

An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. It allows authenticated users to exploit Server-Side Request Forgery (SSRF) due to improper input sanitization and misconfigured domain whitelisting. This issue permits unauthorized HTTP requests to be sent to internal services, which can lead to Remote Code Execution (RCE) by chaining Command Injection within the internal service. When combined with existing XSS vulnerabilities, this SSRF issue can further facilitate Remote Code Execution (RCE).

Scores

CVSS v3 8.8
EPSS 0.2030
EPSS Percentile 97.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-918
Status published
Products (2)
zimbra/collaboration 8.8.15 (43 CPE variants)
zimbra/collaboration 9.0.0 (7 CPE variants)
Published Oct 22, 2024
Tracked Since Feb 18, 2026