CVE-2019-9670
Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
Vulnerability Description
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
Affected Platforms (CPE)
📦
Synacor
Zimbra Collaboration Suite
>= 8.7.0 and < 8.7.11📦
Synacor
Zimbra Collaboration Suite
= 8.7.11📦
Synacor
Zimbra Collaboration Suite
= 8.7.11📦
Synacor
Zimbra Collaboration Suite
= 8.7.11📦
Synacor
Zimbra Collaboration Suite
= 8.7.11📦
Synacor
Zimbra Collaboration Suite
= 8.7.11📦
Synacor
Zimbra Collaboration Suite
= 8.7.11📦
Synacor
Zimbra Collaboration Suite
= 8.7.11📦
Synacor
Zimbra Collaboration Suite
= 8.7.11📦
Synacor
Zimbra Collaboration Suite
= 8.7.11📦
Synacor
