Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-67809

Опубликовано: 15 дек. 2025
Источник: nvd
CVSS3: 4.7
EPSS Низкий

Описание

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr Zimlet used by Zimbra Collaboration. Because these credentials are embedded directly in the Zimlet, any unauthorized party could retrieve them and misuse the Flickr integration. An attacker with access to the exposed credentials could impersonate the legitimate application and initiate valid Flickr OAuth flows. If a user is tricked into approving such a request, the attacker could gain access to the user s Flickr data. The hardcoded credentials have since been removed from the Zimlet code, and the associated key has been revoked.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:*
Версия от 10.0.0 (включая) до 10.1.13 (исключая)

EPSS

Процентиль: 9%
0.00033
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 4.7
github
около 2 месяцев назад

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr Zimlet used by Zimbra Collaboration. Because these credentials are embedded directly in the Zimlet, any unauthorized party could retrieve them and misuse the Flickr integration. An attacker with access to the exposed credentials could impersonate the legitimate application and initiate valid Flickr OAuth flows. If a user is tricked into approving such a request, the attacker could gain access to the user s Flickr data. The hardcoded credentials have since been removed from the Zimlet code, and the associated key has been revoked.

EPSS

Процентиль: 9%
0.00033
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-798