Executive brief
Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in the MailboxImportServlet (mboximport functionality). An attacker can bypass authentication to upload a malicious ZIP archive, which, due to an incomplete fix for CVE-2022-27925, allows for directory traversal and remote code execution.
Affected products
- Synacor Zimbra Collaboration Suite (ZCS) 8.8.15, 9.0.0
Timeline
- 2022-08-11: disclosed
- 2022-08-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-08-11: advisory