Loading HuntDB...

Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability

Added July 7, 2025 Due July 28, 2025 CVE-2019-9621
Overdue Synacor / Zimbra Collaboration Suite (ZCS) CWE-918 CWE-807

Description

Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component.

Required Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

References

Additional Information

Catalog Version
2025.07.07
Catalog Released
July 7, 2025
Days Until Due
0 days
Last Updated
2 months, 3 weeks ago