Path traversal in Zimbra Collaboration - CVE-2022-27925
Published: August 8, 2022 / Updated: December 19, 2023
Vulnerability details
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in file name inside a zip archive in mboximport (MailboxImportServlet). A remote user can upload a specially crafted archive and write files to an arbitrary location on the system.
Affected software
How to mitigate CVE-2022-27925
Links to Public Exploits and PoC-codes
- Exploit #9450 - CVE-2022-27925-Revshell (Python Script to exploit Zimbra Auth Bypass + RCE (CVE-2022-27925)) (December 19, 2023)
- Exploit #8421 - CVE-2022-27925 (A loader for zimbra 2022 rce (cve-2022-27925)) (October 2, 2022)
- Exploit #8370 - CVE-2022-27925-Revshell () (September 18, 2022)
- Exploit #8358 - CVE-2022-27925 (CVE-2022-27925 nuclei template) (September 12, 2022)
- Exploit #8353 - CVE-2022-27925 (Zimbra Unauthenticated Remote Code Execution Exploit (CVE-2022-27925)) (September 7, 2022)
- Exploit #8281 - Zip Path Traversal in Zimbra (mboximport) (CVE-2022-27925) (August 23, 2022)
- Exploit #8278 - CVE-2022-27925 (Zimbra CVE-2022-27925 PoC) (August 21, 2022)
- Exploit #8276 - CVE-2022-27925 () (August 21, 2022)
- Exploit #8271 - CVE-2022-27925 () (August 20, 2022)
- Exploit #8270 - Zimbra_CVE-2022-37042-_CVE-2022-27925 () (August 20, 2022)
- Exploit #8255 - CVE-2022-27925 () (August 16, 2022)
- Exploit #8243 - CVE-2022-27925-PoC (Zimbra RCE simple poc) (August 13, 2022)