PT-2021-7280 · Zimbra · Zimbra Collaboration
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Zimbra Collaboration Suite versions 8.8.15 and 9.0
Description
The
mboximport function allows an authenticated user with administrator rights to upload a ZIP archive containing arbitrary files. This can lead to directory traversal, which is a method used to access files and directories that are stored outside the web root folder. An attacker could exploit this to upload dangerous file types to the system.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Unrestricted File Upload
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zimbra Collaboration