logo

SQLi, XSS, And SSRF: Breaking Down Zimbra’s Latest Security Threats

ID: a4635ed6-33f5-56d7-82f4-6a829012cfe3

STIX ID: report--a4635ed6-33f5-56d7-82f4-6a829012cfe3

Feed Name: Cyble Blog

Threat Score
60/100

Date Published: 2025-03-25

Date Updated: 2026-07-16

...
...

This advisory details three vulnerabilities in Zimbra Collaboration Suite—stored XSS (CVE-2025-27915), SQL injection in the ZimbraSyncService SOAP endpoint (CVE-2025-25064), and an SSRF in the RSS feed parser (CVE-2025-25065)—affecting ZCS 9.0, 10.0, and 10.1 versions prior to recent patches. Each flaw can enable session hijacking, unauthorized email forwarding, data exfiltration, or internal resource access; administrators are urged to apply the latest patches immediately and implement input validation, parameterized queries, WAFs, outbound request restrictions, network segmentation, and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.