Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Jan 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
kev
|

Status: PUBLISHED
Assigner: mitre
Published: 2022-04-20T23:23:25.000Z
Updated: 2025-01-29T16:29:13.767Z
Reserved: 2022-03-25T00:00:00.000Z
Link: CVE-2022-27925

Updated: 2024-08-03T05:41:10.911Z

Status : Modified
Published: 2022-04-21T00:15:08.407
Modified: 2025-02-25T02:00:02.097
Link: CVE-2022-27925

No data.