HIGH

CVE-2025-68645

Synacor Zimbra Collaboration Suite 2025-12-22 CVSS v3.1
CVSS
8.8
KEV

Description

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.

Summary dbcve.org

This is a Local File Inclusion (LFI) vulnerability in Zimbra Collaboration Suite's Webmail Classic UI. The RestFilter servlet improperly handles user-supplied request parameters, allowing an unauthenticated remote attacker to craft requests to the /h/rest endpoint to include arbitrary files from the WebRoot directory.

Mitigation

Apply the vendor patch from Zimbra for ZCS 10.0.x and 10.1.x when available; as an interim measure, consider restricting or blocking unauthenticated access to the /h/rest endpoint at the perimeter.

Weakness (CWE)

CWE-98 PHP File Inclusion (RFI/LFI)

EPSS Score

48.87%
Probability of exploitation in next 30 days
98.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE