CVE-2022-27925

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
synacorzimbra_collaboration_suite
8.8.15
synacorzimbra_collaboration_suite
9.0.0
synacorzimbra_collaboration_suite
9.0.0:p1
synacorzimbra_collaboration_suite
9.0.0:p10
synacorzimbra_collaboration_suite
9.0.0:p11
synacorzimbra_collaboration_suite
9.0.0:p12
synacorzimbra_collaboration_suite
9.0.0:p13
synacorzimbra_collaboration_suite
9.0.0:p14
synacorzimbra_collaboration_suite
9.0.0:p15
synacorzimbra_collaboration_suite
9.0.0:p16
synacorzimbra_collaboration_suite
9.0.0:p17
synacorzimbra_collaboration_suite
9.0.0:p18
synacorzimbra_collaboration_suite
9.0.0:p19
synacorzimbra_collaboration_suite
9.0.0:p2
synacorzimbra_collaboration_suite
9.0.0:p20
synacorzimbra_collaboration_suite
9.0.0:p21
synacorzimbra_collaboration_suite
9.0.0:p22
synacorzimbra_collaboration_suite
9.0.0:p23
synacorzimbra_collaboration_suite
9.0.0:p3
synacorzimbra_collaboration_suite
9.0.0:p4
synacorzimbra_collaboration_suite
9.0.0:p5
synacorzimbra_collaboration_suite
9.0.0:p6
synacorzimbra_collaboration_suite
9.0.0:p7
synacorzimbra_collaboration_suite
9.0.0:p8
synacorzimbra_collaboration_suite
9.0.0:p9
𝑥
= Vulnerable software versions