Overview
Description
This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.
Statistics
- 1 Post
- 1 Interaction
Last activity: 7 hours ago
Overview
Description
This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.
Statistics
- 1 Post
- 1 Interaction
Last activity: 7 hours ago
Overview
Description
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.
Statistics
- 1 Post
- 1 Interaction
Last activity: 16 hours ago
Bluesky
C'est la fête du mail ðŸ˜
âš SmarterMail
CVE-2025-52691
CVSS 10.0
🡇Téléversement pré-auth de fichier /api/upload
Detect github.com/rxerium/CVE-...
Pistes pour exploit www.nccgroup.com/research-blo...
âš Zimbra
CVE-2025-68645
CVSS 8.8
🡅Téléchargement pré-auth de fichier (LFI)
PoC cible/h/rest?javax...