Executive brief
The mailboxd component in Synacor Zimbra Collaboration Suite (ZCS) contains an XML External Entity (XXE) injection vulnerability. The flaw is specifically present in the Autodiscover/Autodiscover.xml handler, allowing remote attackers to access sensitive information or potentially achieve further compromise.
Affected products
- Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10
Timeline
- 2019-03-11: disclosed: Initial CVE assignment/publication date based on CVE ID year and external references.
- 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-01-10: advisory: NVD publication date.
- 2022-01-10: exploited: Confirmed as exploited in the wild by CISA.