mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2019-05-29 22:29
Updated : 2025-04-03 20:28
NVD link : CVE-2019-9670
Mitre link : CVE-2019-9670
CVE.ORG link : CVE-2019-9670
JSON object : View
Products Affected
synacor
- zimbra_collaboration_suite
CWE
CWE-611
Improper Restriction of XML External Entity Reference