HackerFeeds
All CVEs

CVE-2022-37042

CRITICAL9.8
CISA KEV

Published 2022-08-12 · Updated 2026-08-04 · Source cve@mitre.org

Description

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CWE-22CWE-22

CISA Known-Exploited Vulnerability

Product: SynacorZimbra Collaboration Suite (ZCS)

Name: Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability

Date added: 2022-08-11 · Due: 2022-09-01

USED IN RANSOMWARE

Required action: Apply updates per vendor instructions.

View on NVD