THREATOPS
THREAT OPSThreat News › [NVD] CVE-2022-27925 (HIGH 7.2) — Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

[NVD] CVE-2022-27925 (HIGH 7.2) — Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

lownvdPublished 2022-04-21

CVE-2022-27925 CVSS: 7.2 HIGH Published: 2022-04-21T00:15:08.407

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2022-27925