peter bassill · operator
$ cve CVE-2022-27925 JSON

CVE-2022-27925 KEV

7.2
HIGH · CVSS 3.1 · EPSS 98.7% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-09-01.

Description

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

Scoring

CVSS7.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS98.68% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-22
On CISA KEVyes — remediate by 2022-09-01
Public exploitnone known
Published2022-04-21
Last modified2026-08-04

CISA KEV

NameSynacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
Added2022-08-11
Due2022-09-01
Vendor / productSynacor / Zimbra Collaboration Suite (ZCS)
Ransomware useknown

Affected (1)

VendorProduct
synacorzimbra collaboration suite

References

→ the Explorer  ·  watch your stack  ·  NVD