Lucene search

K
cvelistMitreCVELIST:CVE-2022-27925
HistoryApr 20, 2022 - 11:23 p.m.

CVE-2022-27925

2022-04-2023:23:25
mitre
www.cve.org
4
zimbra collaboration
arbitrary file upload
directory traversal

AI Score

7.4

Confidence

High

EPSS

0.948

Percentile

99.3%

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.