跳转到帖子

Unauthenticated Local File Inclusion in zimbraAdmin interface via "packages" parameter

recommended_posts

发布于
  • Members

Unauthenticated Local File Inclusion in zimbraAdmin interface via "packages" parameter

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:C/I:N/A:N)
Published
08/12/2024
Created
01/16/2025
Added
01/10/2025
Modified
01/20/2025

Description

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability involves unauthenticated local file inclusion (LFI) in a web application, specifically impacting the handling of the packages parameter. Attackers can exploit this flaw to include arbitrary local files without authentication, potentially leading to unauthorized access to sensitive information. The vulnerability is limited to files within a specific directory.

Solution(s)

  • zimbra-collaboration-upgrade-latest

References

  • https://attackerkb.com/topics/cve-2024-33535
  • CVE - 2024-33535
  • https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.8#Security_Fixes
  • https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P40#Security_Fixes
  • 查看数 694
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…