{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2020-7796",
  "revision": 1,
  "title": "Zimbra Collaboration — request forgery through the WebEx zimlet",
  "summary": "Zimbra Collaboration before 8.8.15 Patch 7, with the WebEx zimlet installed and its page handling enabled, lets an attacker make the server issue requests of their choosing to systems it can reach.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.84418,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-02-17",
    "prerequisites": "Network access to a Zimbra server with the WebEx zimlet installed and enabled."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "Zimbra Collaboration 8.8.15 Patch 7"
    ]
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Apply Zimbra 8.8.15 Patch 7 or later now; where the WebEx zimlet is not needed, remove it rather than leaving it installed and idle.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2020-7796",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2020-7796",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2020-7796",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-7796",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P7"
    }
  ],
  "published_at": "2020-02-18T22:15:10.013Z",
  "issued_at": "2026-09-24T08:51:39.744Z",
  "tags": [
    "zimbra",
    "webmail",
    "ssrf",
    "kev"
  ]
}
