CVE-2020-7796criticalunder attackCWE-918

CVE-2020-7796

Published · Updated

95Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 84%
from disclosure to weapon
Published on NVDFeb 18
CISA KEV+2191d
exploitation probability
84%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2026-03-10

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

Zimbra email server versions before 8.8.15 Patch 7 have a flaw in the WebEx plugin that allows attackers to make the server connect to internal or external systems on their behalf, potentially exposing sensitive data or compromising internal infrastructure.

Technical detail

Server-Side Request Forgery (SSRF) vulnerability in Zimbra Collaboration Suite WebEx zimlet when JSP execution is enabled. Attackers can craft requests to the zimlet endpoint to force the server to make HTTP requests to arbitrary internal or external targets, bypassing network controls and potentially accessing restricted resources or metadata services.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a