{"id":"CVE-2022-27925","title":"Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it","summary":"Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, l…","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-22","CWE-22"],"vendor":"synacor","product":"zimbra_collaboration_suite","affected":["zimbra_collaboration_suite = 8.8.15","zimbra_collaboration_suite = 9.0.0"],"published":"2022-04-21","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-27925","references":[{"url":"http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html","label":"cve@mitre.org"},{"url":"https://wiki.zimbra.com/wiki/Security_Center","label":"cve@mitre.org"},{"url":"https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24","label":"cve@mitre.org"},{"url":"https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories","label":"cve@mitre.org"},{"url":"http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://wiki.zimbra.com/wiki/Security_Center","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-27925","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.98676,"epssPercentile":0.99924,"kev":true,"kevDateAdded":"2022-08-11","kevDueDate":"2022-09-01","kevRansomware":true,"exploited":true,"ingestedAt":"2026-08-04T05:36:12.246Z","exploits":{"github":12,"githubRepos":["https://github.com/vnhacker1337/CVE-2022-27925-PoC","https://github.com/huahuatzt/CVE-2022-27925","https://github.com/miko550/CVE-2022-27925"],"metasploit":["exploit/linux/http/zimbra_mboximport_cve_2022_27925"],"checkedAt":"2026-09-21T15:25:20.914Z"},"exploitAvailable":true,"slug":"CVE-2022-27925","body":"## Overview\n\nZimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.\n\n## Affected\n\n- `zimbra_collaboration_suite = 8.8.15`\n- `zimbra_collaboration_suite = 9.0.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":89,"depthScoreParts":{"impact":39.6,"likelihood":19.7,"exploitation":25,"ransomware":5},"changes":[{"seq":4609,"id":"CVE-2022-27925","ts":1788887193958,"field":"exploit_available","old":"false","new":"true"},{"seq":3492,"id":"CVE-2022-27925","ts":1788886310389,"field":"exploit_available","old":"true","new":"false"},{"seq":2346,"id":"CVE-2022-27925","ts":1788882979877,"field":"exploit_available","old":"false","new":"true"},{"seq":1375,"id":"CVE-2022-27925","ts":1788882392493,"field":"exploit_available","old":"true","new":"false"},{"seq":489,"id":"CVE-2022-27925","ts":1788881828336,"field":"exploit_available","old":"false","new":"true"}]}