CRITICAL

CVE-2024-45519

Synacor Zimbra Collaboration Suite 2024-10-02 CVSS v3.1
CVSS
9.8
KEV

Description

The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.

Summary dbcve.org

The postjournal service in Zimbra Collaboration contains a command injection vulnerability allowing unauthenticated attackers to execute arbitrary commands on affected systems. The flaw affects multiple versions across ZCS 8.8.15, 9.x, 10.x, and 10.1.x prior to their respective patched releases.

Mitigation

Upgrade Zimbra Collaboration to version 8.8.15 Patch 46, 9.0.0 Patch 41, 10.0.9, or 10.1.1 or later to remediate this vulnerability.

Proof of Concept

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

99.91%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE