HomeZimbraCVE-2025-67809

CVE-2025-67809

MEDIUM
4.7CVSS
Published: 2025-12-15
Updated: 2025-12-30
AI Analysis

Description

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr Zimlet used by Zimbra Collaboration. Because these credentials are embedded directly in the Zimlet, any unauthorized party could retrieve them and misuse the Flickr integration. An attacker with access to the exposed credentials could impersonate the legitimate application and initiate valid Flickr OAuth flows. If a user is tricked into approving such a request, the attacker could gain access to the user s Flickr data. The hardcoded credentials have since been removed from the Zimlet code, and the associated key has been revoked.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
network
Complexity
high
Privileges
none
User Action
required
Scope
changed
Confidentiality
low
Integrity
low
Availability
none
Weaknesses
CWE-798

Metadata

Primary Vendor
ZIMBRA
Published
12/15/2025
Last Modified
12/30/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

zimbra : collaboration

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief