CVE-2025-32354

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-32354
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-32354.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-32354
Published
2025-04-29T16:15:34Z
Modified
2025-06-12T11:03:11.633470Z
Summary
[none]
Details

In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/graphql) of Zimbra webmail due to a lack of CSRF token validation. This allows attackers to perform unauthorized GraphQL operations, such as modifying contacts, changing account settings, and accessing sensitive user data when an authenticated user visits a malicious website.

References

Affected packages

Git / github.com/zimbra/zm-build

Affected ranges

Type
GIT
Repo
https://github.com/zimbra/zm-build
Events
Type
GIT
Repo
https://github.com/zimbra/zm-mailbox
Events
Type
GIT
Repo
https://github.com/zimbra/zm-zcs-lib
Events

Affected versions

10.*

10.0.0
10.0.0-GA
10.1.0
10.1.1
10.1.2
10.1.3

9.*

9.0.0