Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j5r7-6rm3-99mm

Опубликовано: 22 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

EPSS

Процентиль: 100%
0.9431
Критический

7.2 High

CVSS3

Дефекты

CWE-22
CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
почти 4 года назад

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

CVSS3: 7.1
fstec
около 4 лет назад

Уязвимость функции mboximport корпоративной системы управления электронной почтой Zimbra Collaboration Suite (ZCS), позволяющая нарушителю загрузить произвольные файлы в систему

EPSS

Процентиль: 100%
0.9431
Критический

7.2 High

CVSS3

Дефекты

CWE-22
CWE-434