CVE-2022-37043

Source
https://cve.org/CVERecord?id=CVE-2022-37043
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-37043.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-37043
Published
2022-08-11T19:40:25Z
Modified
2026-07-15T01:49:01.749712752Z
Summary
[none]
Details

An issue was discovered in the webmail component in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. When using preauth, CSRF tokens are not checked on some POST endpoints. Thus, when an authenticated user views an attacker-controlled page, a request will be sent to the application that appears to be intended. The CSRF token is omitted from the request, but the request still succeeds.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/37xxx/CVE-2022-37043.json"
}
References

Affected packages

Git / github.com/zimbra/zm-build

Affected ranges

Type
GIT
Repo
https://github.com/zimbra/zm-build
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:zimbra:collaboration:8.8.15:-:*:*:*:*:*:*",
        "cpe:2.3:a:zimbra:collaboration:9.0.0:-:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "8.8.15-NA"
        },
        {
            "last_affected": "8.8.15-NA"
        },
        {
            "introduced": "9.0.0-NA"
        },
        {
            "last_affected": "9.0.0-NA"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

8.*
8.8.15-NA
9.*
9.0.0-NA

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-37043.json"