CVE-2019-9670
29.05.2019, 22:29
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.Enginsight
Vendor | Product | Version |
---|---|---|
synacor | zimbra_collaboration_suite | 8.7.0 ≤ 𝑥 < 8.7.11 |
synacor | zimbra_collaboration_suite | 8.7.11 |
synacor | zimbra_collaboration_suite | 8.7.11:p1 |
synacor | zimbra_collaboration_suite | 8.7.11:p2 |
synacor | zimbra_collaboration_suite | 8.7.11:p3 |
synacor | zimbra_collaboration_suite | 8.7.11:p4 |
synacor | zimbra_collaboration_suite | 8.7.11:p5 |
synacor | zimbra_collaboration_suite | 8.7.11:p6 |
synacor | zimbra_collaboration_suite | 8.7.11:p7 |
synacor | zimbra_collaboration_suite | 8.7.11:p8 |
synacor | zimbra_collaboration_suite | 8.7.11:p9 |
𝑥
= Vulnerable software versions
References