CVE-2025-68645
Description
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.
Summary dbcve.org
This is a Local File Inclusion (LFI) vulnerability in Zimbra Collaboration Suite's Webmail Classic UI. The RestFilter servlet improperly handles user-supplied request parameters, allowing an unauthenticated remote attacker to craft requests to the /h/rest endpoint to include arbitrary files from the WebRoot directory.
Mitigation
Apply the vendor patch from Zimbra for ZCS 10.0.x and 10.1.x when available; as an interim measure, consider restricting or blocking unauthenticated access to the /h/rest endpoint at the perimeter.