Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9g5r-3vrr-xfcm

Опубликовано: 13 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.

EPSS

Процентиль: 100%
0.94333
Критический

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.

CVSS3: 9.8
fstec
больше 3 лет назад

Уязвимость функции mboximport корпоративной системы управления электронной почтой Zimbra Collaboration Suite (ZCS), позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 100%
0.94333
Критический

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-287