CyberSec.Space Logo
Back to CVE Browser

CVE-2022-27925

πŸ”₯ Known Exploited (CISA KEV)HIGH
7.2
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2022-04-21
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

Affected Platforms (CPE)

πŸ“¦
Synacor

Zimbra Collaboration Suite

= 8.8.15= 9.0.0

References & Advisories

Related Vulnerabilities