{"id":"CVE-2025-32354","details":"In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/graphql) of Zimbra webmail due to a lack of CSRF token validation. This allows attackers to perform unauthorized GraphQL operations, such as modifying contacts, changing account settings, and accessing sensitive user data when an authenticated user visits a malicious website.","modified":"2026-09-14T08:05:51.872412Z","published":"2025-04-29T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/32xxx/CVE-2025-32354.json","unresolved_ranges":[{"extracted_events":[{"introduced":"9.0"},{"fixed":"10.1"}],"source":"DESCRIPTION"}],"cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://wiki.zimbra.com/wiki/Security_Center"},{"type":"WEB","url":"https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.4#Security_Fixes"},{"type":"WEB","url":"https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/32xxx/CVE-2025-32354.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32354"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-build","events":[{"introduced":"b6cd8f69d2761c014d4a3807f0bdee0011386444"},{"fixed":"16fcfbde0910368571419d9becd0401a95af6e7f"}],"database_specific":{"cpe":"cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"9.0.0"},{"fixed":"10.1.4"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-32354.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-mailbox","events":[{"introduced":"2ec276e0cd140c34d2e8aa6e2260a10901e43a9d"},{"fixed":"02deeb6294c2327768a7177124ea3bab2a56e56c"}],"database_specific":{"extracted_events":[{"introduced":"9.0.0"},{"fixed":"10.1.4"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-32354.json","vanir_signatures_modified":"2026-09-14T08:05:51Z","vanir_signatures":[{"target":{"file":"store/src/java/com/zimbra/cs/service/account/ChangePassword.java","function":"handle"},"deprecated":false,"digest":{"function_hash":"250239021129922179859369307689305685860","length":2910},"id":"CVE-2025-32354-80107f44","signature_type":"Function","signature_version":"v1","source":"https://github.com/zimbra/zm-mailbox/commit/02deeb6294c2327768a7177124ea3bab2a56e56c"},{"target":{"file":"store/src/java/com/zimbra/cs/service/account/ChangePassword.java"},"deprecated":false,"digest":{"line_hashes":["100352541356968744543459554936932541435","34980778564753151690669805825885263298","163615395104885010895005793672519100036","324766885195200298088869019113793247780"],"threshold":0.9},"id":"CVE-2025-32354-f5d96fd7","signature_type":"Line","signature_version":"v1","source":"https://github.com/zimbra/zm-mailbox/commit/02deeb6294c2327768a7177124ea3bab2a56e56c"}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-zcs-lib","events":[{"introduced":"08274721e99c2522952c640cd42e4d0cf676d432"},{"fixed":"544f6ac469b9b633b2d42a8d66b8db8b24043708"}],"database_specific":{"extracted_events":[{"introduced":"9.0.0"},{"fixed":"10.1.4"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*"}}],"versions":["10.1.1","10.1.0","10.0.0-GA","10.0.0","9.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-32354.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}