PT-2021-7280 · Zimbra · Zimbra Collaboration

·

CVE-2022-27925

·

Published

2021-12-27

·

Updated

2026-08-24

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration Suite versions 8.8.15 and 9.0
Description The mboximport function allows an authenticated user with administrator rights to upload a ZIP archive containing arbitrary files. This can lead to directory traversal, which is a method used to access files and directories that are stored outside the web root folder. An attacker could exploit this to upload dangerous file types to the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Unrestricted File Upload

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05086
CVE-2022-27925

Affected Products

Zimbra Collaboration