Описание
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- Vendor Advisory
- Release NotesVendor Advisory
- Vendor Advisory
- ExploitThird Party AdvisoryVDB Entry
- Vendor Advisory
- Release NotesVendor Advisory
- Vendor Advisory
- US Government Resource
Уязвимые конфигурации
Одно из
EPSS
7.2 High
CVSS3
6.5 Medium
CVSS2
Дефекты
Связанные уязвимости
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
Уязвимость функции mboximport корпоративной системы управления электронной почтой Zimbra Collaboration Suite (ZCS), позволяющая нарушителю загрузить произвольные файлы в систему
EPSS
7.2 High
CVSS3
6.5 Medium
CVSS2