在 Zimbra Collaboration (ZCS) 10.1.17 版本之前,Zimbra Briefcase 文档编辑功能中存在一个路径遍历漏洞,该漏洞是由于对 packages 参数验证不当所致。经过身份验证的攻击者可以通过构造包含路径遍历序列的恶意请求来利用此漏洞,可能导致 Web 应用程序目录中的敏感文件被未授权访问和泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Zimbra | Collaboration | < 10.1.17 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zimbra | Collaboration | 0 ~ 10.1.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73570 | 8.9 HIGH | Zimbra Collaboration 命令注入漏洞 |
| CVE-2026-73576 | 6.3 MEDIUM | Zimbra <10.1.17 OnlyOffice弱密钥生成致JWT伪造 |
| CVE-2026-73572 | 6.1 MEDIUM | Zimbra <10.1.17 存储型XSS漏洞 |
| CVE-2026-73575 | 3.1 LOW | ZCS<10.1.17 CSRF漏洞 |
| CVE-2026-73571 | 3.1 LOW | Zimbra Collaboration <10.1.17 授权绕过漏洞 |
| CVE-2026-73574 | 3.1 LOW | Zimbra<10.1.17经典Web客户端LFI漏洞 |
No comments yet