Threats Tagged 'cve-2025-67809'
View all threats tagged with 'cve-2025-67809'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-67809'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2025-67809 is a medium severity vulnerability in Zimbra Collaboration Suite (ZCS) versions 10.0 and 10.1 involving a hardcoded Flickr API key and secret embedded in the publicly accessible Flickr Zimlet. This exposure allows unauthorized parties to extract these credentials and misuse the Flickr integration by impersonating the legitimate application and initiating OAuth flows. If a user is tricked into approving such a request, the attacker could gain access to the user's Flickr data, impacting confidentiality and integrity. The vulnerability does not allow direct system compromise or availability disruption and requires user interaction and high attack complexity. The hardcoded credentials have been removed and revoked in later versions. European organizations using affected Zimbra versions with Flickr Zimlet enabled should update promptly and educate users about phishing risks related to OAuth approvals. Join the discussion | CVE Database V5 | 12/15/2025, 00:00:00 UTC Added: 12/15/2025, 19:45:18 UTC |
Showing 1 to 1 of 1 result