Executive brief
The postjournal service in Synacor Zimbra Collaboration Suite (ZCS) contains a vulnerability that allows unauthenticated remote attackers to execute arbitrary commands. This issue stems from improper neutralization of special elements used in an OS command.
Affected products
- Synacor Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1
Timeline
- 2024-10-03: disclosed
- 2024-10-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- exploited: Reported as exploited in the wild.