A AegiFlow
HIGHCVSS 7.2KNOWN EXPLOITEDRANSOMWARE: KNOWN

CVE-2022-27925

CVE-2022-27925 updated by NVD

Published
2022-08-11
Modified
2026-09-21
Sources
cisa-kev, nvd

Summary

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.