S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-7796 Scanner

CVE-2020-7796 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in Zimbra Collaboration Suite (ZCS)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-7796
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Zimbra Collaboration Suite (ZCS) is a comprehensive email and collaboration platform used by organizations of all sizes. It is specifically designed to help businesses communicate more efficiently while also streamlining their workflows. The platform offers a range of features, including email, calendaring, tasks, file sharing, and social media integration. ZCS is a popular choice for organizations looking for a flexible, secure, and highly customizable collaboration solution.

Recently, a vulnerability known as CVE-2020-7796 was detected in Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7. This flaw allows an attacker to conduct a Server-Side Request Forgery (SSRF) attack. SSRF is a type of attack wherein an attacker can send unauthorized requests to a server, which can then potentially allow them to access sensitive information or resources that are normally blocked by a firewall or other security measures.

When exploited, this vulnerability can lead to serious consequences, including data breaches and unauthorized access to sensitive information. An attacker may be able to steal login credentials, inject malware, or perform other malicious activities. Furthermore, organizations using Zimbra Collaboration Suite (ZCS) should be extremely cautious, as the vulnerability is particularly dangerous due to the platform's extensive role in enterprise-level communications.

At s4e.io, we offer a range of pro features that can help organizations protect against vulnerabilities like CVE-2020-7796. With our platform, businesses can quickly and easily identify potential risks to their digital assets, prioritize security issues, and implement effective security measures to protect against cyber-attacks. Our team of experts is dedicated to helping organizations stay safe and secure in an ever-changing cybersecurity landscape.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautionary measures that businesses can take. These include, but are not limited to:

  • Installing the latest ZCS patch to fix the SSRF vulnerability.
  • Disabling the affected WebEx zimlet when not in use.
  • Limiting access to the platform to only those who need it.
  • Employing multi-factor authentication to protect against unauthorized access to the platform.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-7796 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in Zimbra Collaboration Suite (ZCS) | S4E