CyberSec.Space Logo
返回 CVE 浏览器

CVE-2025-68645

🔥 Known Exploited (CISA KEV)HIGH
8.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-12-22
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.

Affected Platforms (CPE)

📦
Synacor

Zimbra Collaboration Suite

>= 10.0.0 and < 10.0.18>= 10.1.0 and < 10.1.13

References & Advisories

相关漏洞威胁