ZeroHour

CVE-2025-25065

CVSS 3.1
5.3 medium
EPSS
<1%p46
Published
()
Modified
Description

SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.

Vendors
synacor
Products
zimbra collaboration suite
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news