CVE-2019-9670
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- March 11, 2019
- Published Date
- May 29, 2019
- Last Updated
- February 07, 2025
- Vendor
- n/a
- Product
- n/a
- Description
- mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
CVSS Scores
SSVC Information
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
References
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
https://bugzilla.zimbra.com/show_bug.cgi?id=109129
http://www.rapid7.com/db/modules/exploit/linux/http/zimbra_xxe_rce
http://packetstormsecurity.com/files/152487/Zimbra-Collaboration-Autodiscover-Servlet-XXE-ProxyServlet-SSRF.html
https://www.exploit-db.com/exploits/46693/
https://isc.sans.edu/forums/diary/CVE20199670+Zimbra+Collaboration+Suite+XXE+vulnerability/27570/
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-01-10 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/zimbra_xxe_rce.rb | 2025-04-29 11:01:16 UTC |
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-9670.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
Cappricio-Securities/CVE-2019-9670
Type: github • Created: 2024-04-24 12:32:18 UTC • Stars: 0
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.