Zimbra Releases Security Updates for SQL Injection, Stored XSS, and SSRF Vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-25064 +1 in the same advisory: …25065 | Authenticated SQL Injection in Zimbra Collaboration ZimbraSync Service CVE-2025-25064 is a SQL injection flaw in the ZimbraSync Service SOAP endpoint of Zimbra Collaboration Suite, caused by insufficient sanitization of a user-supplied parameter. An authenticated attacker triggers it by sending a crafted SOAP request with malicious content in a specific parameter, allowing arbitrary SQL queries to be injected into the backend database. Successful exploitation can let the attacker retrieve email metadata from the database, with the high CVSS 8.8 score reflecting potentially serious confidentiality, integrity and availability impact. It affects Zimbra Collaboration 10.0.x prior to 10.0.12 and 10.1.x prior to 10.1.4, so any organization running those branches with the sync service exposed is in scope. As of the advisory date there is no public proof-of-concept, it is not listed in CISA KEV, but its EPSS of 36.7% (98th percentile) indicates an elevated likelihood of exploitation attempts within 30 days, and fixes were shipped in Zimbra's recent security release alongside patches for stored XSS and SSRF issues. Do: Upgrade Zimbra Collaboration to 10.0.12 (for the 10.0.x branch) or 10.1.4 (for the 10.1.x branch), or later, applying the current security patch release which also fixes related stored XSS and SSRF issues. Because exploitation requires authentication, review for suspicious or compromised accounts and restrict exposure of the ZimbraSync Service SOAP endpoint until patched. Monitor vendor advisories for updates on exploitation activity given the elevated EPSS score. | 8.8 group max | 37% |
| largeon the order of tens of thousands of internet-exposed Zimbra servers, of which a substantial share run the affected 10.0.x/10.1.x branches (roughly 10k+… |
Full article253 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananFeb 10, 2025Vulnerability / Data Protection
Zimbra has released software updates to address critical security flaws in its Collaboration software that, if successfully exploited, could result in information disclosure under certain conditions.
The vulnerability, tracked as CVE-2025-25064, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as an SQL injection bug in the ZimbraSync Service SOAP endpoint affecting versions prior to 10.0.12 and 10.1.4.
Stemming from a lack of adequate sanitization of a user-supplied parameter, the shortcoming could be weaponized by authenticated attackers to inject arbitrary SQL queries that could retrieve email metadata by "manipulating a specific parameter in the request."
Zimbra also said it addressed another critical vulnerability related to stored cross-site scripting (XSS) in the Zimbra Classic Web Client. The flaw is yet to be assigned a CVE identifier.
"The fix strengthens input sanitization and enhances security," the company said in an advisory, adding the issue has been fixed in versions 9.0.0 Patch 44, 10.0.13, and 10.1.5.
Another vulnerability addressed by Zimbra is CVE-2025-25065 (CVSS score: 5.3), a medium-severity server-side request forgery (SSRF) flaw in the RSS feed parser component that allows for unauthorized redirection to internal network endpoints.
The security defect has been patched in versions 9.0.0 Patch 43, 10.0.12, and 10.1.4. Customers are advised to update to the latest versions of Zimbra Collaboration for optimal protection.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/02/zimbra-releases-security-updates-for.html