Zimbra.Collaboration.RestFilter.Local.File.Inclusion

description-logoDescription

This indicates an attack attempt to exploit a Local File Inclusion vulnerability in Zimbra Collaboration.
The vulnerability is due to improper validation of user-supplied inputs. An unauthenticated remote attacker could exploit this vulnerability by sending a crafted request to the target server. Successful exploitation of this vulnerability could lead to information disclosure from the target server.

description-logoOutbreak Alert

A Local File Inclusion (LFI) vulnerability (CVE-2025-68645) exists in the Zimbra Collaboration Suite (ZCS) Webmail Classic UI due to improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft malicious requests, potentially exposing sensitive configuration and application data and aiding further compromise.

View the full Outbreak Alert Report

affected-products-logoAffected Products

Zimbra Collaboration 10.1 versions prior to 10.1.13
Zimbra Collaboration 10.0 versions prior to 10.0.18

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2026-02-17 35.169
Modified
Default_action:pass:drop
2026-01-27 35.158
New