8.8 CVE-2025-68645

CISA Kev Catalog
 

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.
https://nvd.nist.gov/vuln/detail/CVE-2025-68645

Categories

CWE-98

References


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:* >= 10.0.0 < 10.0.18
cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:* >= 10.1.0 < 10.1.13


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry