CVE-2022-27925: Zimbra Collaboration Suite 8.8.15/9.0 - Zip Path Traversal

2026-10-08 PoC Public

Description

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

PoC

id: CVE-2022-27925

info:
  name: Zimbra Collaboration Suite 8.8.15/9.0 - Zip Path Traversal
  author: popy21
  severity: high
  description: |
    Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
  impact: |
    An administrator-authenticated attacker uploads a ZIP whose entries traverse out of the extraction directory, dropping a JSP webshell into the Zimbra webroot for remote code execution as the zimbra user - and CVE-2022-37042 removes the authentication requirement entirely, which is how this pair was mass-exploited in the wild.
  remediation: |
    Apply Zimbra Collaboration 8.8.15 Patch 31 or 9.0.0 Patch 24 (both released 2022-03-30) or later, which also requires the CVE-2022-37042 fix in 8.8.15 Patch 33 / 9.0.0 Patch 26 to close the authentication bypass on the same mboximport endpoint.
  reference:
    - http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html
    - https://wiki.zimbra.com/wiki/Security_Center
    - https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24
    - https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P31
    - https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
    - https://www.volexity.com/blog/2022/08/10/mass-exploitation-of-unauthenticated-zimbra-rce-cve-2022-27925/
    - https://nvd.nist.gov/vuln/detail/CVE-2022-27925
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 7.2
    cve-id: CVE-2022-27925
    cwe-id: CWE-22
    epss-score: 0.98676
    epss-percentile: 0.99923
    cpe: cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:-:*:*:*:*:*:*
  metadata:
    verified: true
    max-request: 1
    vendor: synacor
    product: zimbra_collaboration_suite
    shodan-query: http.title:"Zimbra Collaboration Suite"
    fofa-query: title="Zimbra Collaboration Suite"
  tags: cve,cve2022,synacor,zimbra,zimbra-collaboration-suite,lfi,rce,kev,vkev,passive

http:
  - method: GET
    path:
      - "{{BaseURL}}/js/zimbraMail/share/model/ZmSettings.js"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "Zimbra Collaboration Suite Web Client"

      - type: word
        part: header
        words:
          - "application/x-javascript"

      - type: word
        part: version
        words:
          - "8.8.15"
          - "9.0"

      - type: status
        status:
          - 200

    extractors:
      - type: regex
        name: version
        part: body
        group: 1
        regex:
          - 'CLIENT_VERSION\",\s+{type:ZmSetting.T_CONFIG, defaultValue:\"(.*?)"'
# digest: 4b0a00483046022100d1e587a4cb4e93897522fcc58f5d3ab3f3ac6676f50b111b1b227457cb97031a02210093b6164070c687f0b33678390d8578e1b7bd2689b624e24f4a64b925f0feeced:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.