In Zimbra Collaboration (ZCS) 8.8.15 and 9.0, a closed account (with 2FA and generated passwords) can send e-mail messages when configured for Imap/smtp.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | vendor advisory |
https://wiki.zimbra.com/wiki/Security_Center | release notes |
https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy | product |