- Description
- mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Data from CISA
- Vulnerability name
- Synacor Zimbra Collaboration (ZCS) Improper Restriction of XML External Entity Reference
- Exploit added on
- Jan 10, 2022
- Exploit action due
- Jul 10, 2022
- Required action
- Apply updates per vendor instructions.
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9A91CE8F-5E21-459E-A253-A1706357B82B",
"versionEndExcluding": "8.7.11",
"versionStartIncluding": "8.7.0"
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A98A1461-959C-4FC5-8860-76C3A9605F41"
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F64CBF7B-63AB-4523-84B9-D86F64DAB4BB"
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D411A60B-BFA0-4B47-BF7B-D21AAFFC9E55"
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0ADC2E0E-9365-46AA-85AC-DF2B5C791833"
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5ADA2C87-BDA0-485B-8BF3-EE1E1DC1C4BC"
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E28795C8-62FF-4C68-A469-8A2AD309E28B"
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "08339B97-5558-4DF5-8CB7-6CEB91328CDD"
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "779BE18C-12E4-4F91-A5EC-DAB739003DA0"
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CF7BA64E-2A92-4C8B-8913-E89E6B42ABF7"
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p9:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3999E720-AC7F-45F1-9B72-63366571B6AC"
}
],
"operator": "OR"
}
]
}
]