SSRF vulnerability in Zimbra Collaboration Suite when WebEx zimlet is installed and JSP is enabled. This is a critical server-side vulnerability in a commonly internet-facing email/collaboration platform with active exploitation confirmed by CISA KEV listing.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2020-02-18
Added to CISA KEV: 2026-02-17 2191 DAYS BETWEEN CVE AND KEV
CVE-2020-7796 is a Server-Side Request Forgery (SSRF) vulnerability affecting the Zimbra Collaboration Suite (ZCS) [2]?id=CVE-2020-7796?kagi_q=CVE-2020-7796+details.
Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled. ... "}, {"lang": "es", "value": "Zimbra Collaboration Suite (ZCS) versiones anteriores a 8.8.15 Patch 7, permite un ataque de tipo SSRF cuando WebEx zimlet es instalado y zimlโฆ
Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 is susceptible to server-side request forgery when WebEx zimlet is installed and zimlet JSP is enabled.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog. Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and ... An official website of the United States government NVD MENU ... ... CVE-2020-7796 Detail ... https://www.cisa.gov/known-exploited-vulnโฆ