CyberSec.Space Logo
Back to CVE Browser

CVE-2022-37042

πŸ”₯ Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2022-08-12
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.

Affected Platforms (CPE)

πŸ“¦
Synacor

Zimbra Collaboration Suite

= 8.8.15= 9.0.0

References & Advisories

Related Vulnerabilities