SQLi, XSS, And SSRF: Breaking Down Zimbra’s Latest Security Threats
ID: a4635ed6-33f5-56d7-82f4-6a829012cfe3
STIX ID: report--a4635ed6-33f5-56d7-82f4-6a829012cfe3
Feed Name: Cyble Blog
This advisory details three vulnerabilities in Zimbra Collaboration Suite—stored XSS (CVE-2025-27915), SQL injection in the ZimbraSyncService SOAP endpoint (CVE-2025-25064), and an SSRF in the RSS feed parser (CVE-2025-25065)—affecting ZCS 9.0, 10.0, and 10.1 versions prior to recent patches. Each flaw can enable session hijacking, unauthorized email forwarding, data exfiltration, or internal resource access; administrators are urged to apply the latest patches immediately and implement input validation, parameterized queries, WAFs, outbound request restrictions, network segmentation, and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
