Overview
- Description
- mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Known exploits
Data from CISA
- Vulnerability name
- Synacor Zimbra Collaboration (ZCS) Improper Restriction of XML External Entity Reference
- Exploit added on
- Jan 10, 2022
- Exploit action due
- Jul 10, 2022
- Required action
- Apply updates per vendor instructions.
Weaknesses
- nvd@nist.gov
- CWE-611
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9A91CE8F-5E21-459E-A253-A1706357B82B", "versionEndExcluding": "8.7.11", "versionStartIncluding": "8.7.0" }, { "criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A98A1461-959C-4FC5-8860-76C3A9605F41" }, { "criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F64CBF7B-63AB-4523-84B9-D86F64DAB4BB" }, { "criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D411A60B-BFA0-4B47-BF7B-D21AAFFC9E55" }, { "criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0ADC2E0E-9365-46AA-85AC-DF2B5C791833" }, { "criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5ADA2C87-BDA0-485B-8BF3-EE1E1DC1C4BC" }, { "criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E28795C8-62FF-4C68-A469-8A2AD309E28B" }, { "criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "08339B97-5558-4DF5-8CB7-6CEB91328CDD" }, { "criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p7:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "779BE18C-12E4-4F91-A5EC-DAB739003DA0" }, { "criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p8:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CF7BA64E-2A92-4C8B-8913-E89E6B42ABF7" }, { "criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p9:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3999E720-AC7F-45F1-9B72-63366571B6AC" } ], "operator": "OR" } ] } ]