ZeroHour

CVE-2025-25064

large

Authenticated SQL Injection in Zimbra Collaboration ZimbraSync Service

CVSS 3.1
8.8 high
EPSS
37%p98
Published
()
Modified
AI analysis

CVE-2025-25064 is a SQL injection flaw in the ZimbraSync Service SOAP endpoint of Zimbra Collaboration Suite, caused by insufficient sanitization of a user-supplied parameter. An authenticated attacker triggers it by sending a crafted SOAP request with malicious content in a specific parameter, allowing arbitrary SQL queries to be injected into the backend database. Successful exploitation can let the attacker retrieve email metadata from the database, with the high CVSS 8.8 score reflecting potentially serious confidentiality, integrity and availability impact. It affects Zimbra Collaboration 10.0.x prior to 10.0.12 and 10.1.x prior to 10.1.4, so any organization running those branches with the sync service exposed is in scope. As of the advisory date there is no public proof-of-concept, it is not listed in CISA KEV, but its EPSS of 36.7% (98th percentile) indicates an elevated likelihood of exploitation attempts within 30 days, and fixes were shipped in Zimbra's recent security release alongside patches for stored XSS and SSRF issues.

What to do: Upgrade Zimbra Collaboration to 10.0.12 (for the 10.0.x branch) or 10.1.4 (for the 10.1.x branch), or later, applying the current security patch release which also fixes related stored XSS and SSRF issues. Because exploitation requires authentication, review for suspicious or compromised accounts and restrict exposure of the ZimbraSync Service SOAP endpoint until patched. Monitor vendor advisories for updates on exploitation activity given the elevated EPSS score.

Affected
Synacor Zimbra Collaboration Suite (ZimbraSync Service SOAP endpoint)10.0.x before 10.0.12
Synacor Zimbra Collaboration Suite (ZimbraSync Service SOAP endpoint)10.1.x before 10.1.4
Estimated exposure
largeon the order of tens of thousands of internet-exposed Zimbra servers, of which a substantial share run the affected 10.0.x/10.1.x branches (roughly 10k+… — Public internet scans (e.g., Shodan/Censys) historically show tens of thousands of exposed Zimbra mail servers; only deployments on the relatively current 10.0.x/10.1.x branches are affected, making the precise count uncertain but…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a user-supplied parameter. Authenticated attackers can exploit this vulnerability by manipulating a specific parameter in the request, allowing them to inject arbitrary SQL queries that could retrieve email metadata.

Vendors
synacor
Products
zimbra collaboration suite
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news