HackerFeeds
All CVEs

CVE-2022-27925

HIGH7.2
CISA KEV

Published 2022-04-21 · Updated 2026-08-04 · Source cve@mitre.org

Description

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CWE-22CWE-22

CISA Known-Exploited Vulnerability

Product: SynacorZimbra Collaboration Suite (ZCS)

Name: Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

Date added: 2022-08-11 · Due: 2022-09-01

USED IN RANSOMWARE

Required action: Apply updates per vendor instructions.

View on NVD