Threat Encyclopedia

Zimbra.Collaboration.Mboximport.Unrestricted.File.Upload

description-logoDescription

This indicates an attack attempt to exploit an Unrestricted File Upload Vulnerability in Zimbra Collaboration.
This vulnerability is due to improper input validation. A remote, unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request to the target server. Successfully exploiting this vulnerability can result in uploading of web shells and remote code execution.

affected-products-logoAffected Products

Zimbra Collaboration 8.8.15 before Patch 33
Zimbra Collaboration 9.0.0 before Patch 26

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://wiki.zimbra.com/wiki/Security_Center

Telemetry logoTelemetry