HIGH
CVE-2022-27925
CVSS
7.2
KEV
Description
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
Summary dbcve.org
Zimbra Collaboration versions 8.8.15 and 9.0 contain a directory traversal vulnerability in the mboximport functionality. An authenticated administrator can upload a specially crafted ZIP archive that, when extracted, writes files to arbitrary directories on the system, potentially enabling remote code execution.
Mitigation
Apply vendor-supplied patches or upgrade to a patched ZCS version. Restrict administrator account access and monitor for unusual mboximport activity.
Weakness (CWE)
CWE-22
Path Traversal
EPSS Score
98.68%
Probability of exploitation in next 30 days
99.9th percentile
References
http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html
Exploit, Third Party Advisory, VDB Entry
https://wiki.zimbra.com/wiki/Security_Center
Vendor Advisory
https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24
Release Notes, Vendor Advisory
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-27925
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.