HIGH

CVE-2022-27925

Synacor Zimbra Collaboration Suite 2022-04-21 CVSS v3.1
CVSS
7.2
KEV

Description

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

Summary dbcve.org

Zimbra Collaboration versions 8.8.15 and 9.0 contain a directory traversal vulnerability in the mboximport functionality. An authenticated administrator can upload a specially crafted ZIP archive that, when extracted, writes files to arbitrary directories on the system, potentially enabling remote code execution.

Mitigation

Apply vendor-supplied patches or upgrade to a patched ZCS version. Restrict administrator account access and monitor for unusual mboximport activity.

Proof of Concept

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

98.68%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE