CVE-2022-27925: Zimbra Collaboration Suite 8.8.15/9.0 - Zip Path Traversal
2026-10-08PoC Public
Description
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
PoC
id: CVE-2022-27925
info:
name: Zimbra Collaboration Suite 8.8.15/9.0 - Zip Path Traversal
author: popy21
severity: high
description: |
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
impact: |
An administrator-authenticated attacker uploads a ZIP whose entries traverse out of the extraction directory, dropping a JSP webshell into the Zimbra webroot for remote code execution as the zimbra user - and CVE-2022-37042 removes the authentication requirement entirely, which is how this pair was mass-exploited in the wild.
remediation: |
Apply Zimbra Collaboration 8.8.15 Patch 31 or 9.0.0 Patch 24 (both released 2022-03-30) or later, which also requires the CVE-2022-37042 fix in 8.8.15 Patch 33 / 9.0.0 Patch 26 to close the authentication bypass on the same mboximport endpoint.
reference:
- http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html
- https://wiki.zimbra.com/wiki/Security_Center
- https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P31
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- https://www.volexity.com/blog/2022/08/10/mass-exploitation-of-unauthenticated-zimbra-rce-cve-2022-27925/
- https://nvd.nist.gov/vuln/detail/CVE-2022-27925
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
cvss-score: 7.2
cve-id: CVE-2022-27925
cwe-id: CWE-22
epss-score: 0.98676
epss-percentile: 0.99923
cpe: cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:-:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: synacor
product: zimbra_collaboration_suite
shodan-query: http.title:"Zimbra Collaboration Suite"
fofa-query: title="Zimbra Collaboration Suite"
tags: cve,cve2022,synacor,zimbra,zimbra-collaboration-suite,lfi,rce,kev,vkev,passive
http:
- method: GET
path:
- "{{BaseURL}}/js/zimbraMail/share/model/ZmSettings.js"
matchers-condition: and
matchers:
- type: word
part: body
words:
- "Zimbra Collaboration Suite Web Client"
- type: word
part: header
words:
- "application/x-javascript"
- type: word
part: version
words:
- "8.8.15"
- "9.0"
- type: status
status:
- 200
extractors:
- type: regex
name: version
part: body
group: 1
regex:
- 'CLIENT_VERSION\",\s+{type:ZmSetting.T_CONFIG, defaultValue:\"(.*?)"'
# digest: 4b0a00483046022100d1e587a4cb4e93897522fcc58f5d3ab3f3ac6676f50b111b1b227457cb97031a02210093b6164070c687f0b33678390d8578e1b7bd2689b624e24f4a64b925f0feeced:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.