TROYANOSYVIRUS
Volver a CVEs

CVE-2022-27925

HIGHCISA KEV
7.2

Descripcion

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

Detalles CVE

Puntuacion CVSS v3.17.2
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosHIGH
Interaccion usuarioNONE
Publicado4/21/2022
Ultima modificacion10/31/2025
Fuentekev
Avistamientos honeypot0

CISA KEV

VendedorSynacor
ProductoZimbra Collaboration Suite (ZCS)
Nombre vulnerabilidadSynacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
Fecha inclusion KEV2022-08-11
Fecha limite remediacion2022-09-01
Uso en ransomwareKnown

Productos afectados

synacor:zimbra_collaboration_suite

Debilidades (CWE)

CWE-22CWE-22

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.