Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mc6f-xmmw-r6pv

Опубликовано: 20 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists in the Zimbra Exchange Web Services (EWS) SOAP interface due to improper handling of XML input. An authenticated attacker can submit crafted XML data that is processed by an XML parser with external entity resolution enabled. Successful exploitation may allow disclosure of sensitive local files from the server.

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists in the Zimbra Exchange Web Services (EWS) SOAP interface due to improper handling of XML input. An authenticated attacker can submit crafted XML data that is processed by an XML parser with external entity resolution enabled. Successful exploitation may allow disclosure of sensitive local files from the server.

EPSS

Процентиль: 14%
0.00234
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 4.3
nvd
5 месяцев назад

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists in the Zimbra Exchange Web Services (EWS) SOAP interface due to improper handling of XML input. An authenticated attacker can submit crafted XML data that is processed by an XML parser with external entity resolution enabled. Successful exploitation may allow disclosure of sensitive local files from the server.

CVSS3: 4.3
fstec
6 месяцев назад

Уязвимость корпоративной системы управления электронной почтой Zimbra Collaboration Suite (ZCS), связанная с неверным ограничением XML-ссылок на внешние объекты, позволяющая нарушителю проводить XXE-атаки

EPSS

Процентиль: 14%
0.00234
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-611