CVE-2025-67809

MEDIUM EPSS 14.9%
Published Dec 15, 20256mo ago · Modified Jun 17, 20262w ago
4.7 CVSS 3.1
Medium
Find Similar
Published Dec 15, 2025 6mo ago
Last Modified Jun 17, 2026 2w ago

Description

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr Zimlet used by Zimbra Collaboration. Because these credentials are embedded directly in the Zimlet, any unauthorized party could retrieve them and misuse the Flickr integration. An attacker with access to the exposed credentials could impersonate the legitimate application and initiate valid Flickr OAuth flows. If a user is tricked into approving such a request, the attacker could gain access to the user s Flickr data. The hardcoded credentials have since been removed from the Zimlet code, and the associated key has been revoked.

CVSS Details

Base Score
4.7
Exploitability
1.6
Impact
2.7
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction Required
Scope Changed
Confidentiality Low
Integrity Low
Availability None

Threat Intelligence

EPSS Exploit Probability
14.9% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-798 Use of Hard-coded Credentials Authentication

Affected Products 1

VendorProductVersionRange
zimbracollaboration*≥10.0.0  –  <10.1.13

References 3

  • wiki.zimbra.com https://wiki.zimbra.com/wiki/Security_Center
    Release Notes
  • wiki.zimbra.com https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy
    Product
  • wiki.zimbra.com https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.