GobyVuls/Zimbra/CVE-2019-9670
2020-12-03 20:08:21 +08:00
..
2020-12-03 20:08:21 +08:00
2020-12-03 20:08:21 +08:00

CVE-2019-9670 Zimbra XXE

mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability.

Affected version: Zimbra Collaboration Suite 8.7.0 - 8.7.11

FOFA query rule: app="Zimbra"

Demo