CVE-2025-25064

SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a user-supplied parameter. Authenticated attackers can exploit this vulnerability by manipulating a specific parameter in the request, allowing them to inject arbitrary SQL queries that could retrieve email metadata.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*
cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*

History

11 Jun 2025, 21:18

Type Values Removed Values Added
First Time Synacor
Synacor zimbra Collaboration Suite
References () https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.4#Security_Fixes - () https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.4#Security_Fixes - Release Notes
References () https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.12#Security_Fixes - () https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.12#Security_Fixes - Release Notes
References () https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories - () https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories - Vendor Advisory
CPE cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*

06 Feb 2025, 20:15

Type Values Removed Values Added
Summary SQL injection vulnerability in the ZimbraSyncService SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4. SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a user-supplied parameter. Authenticated attackers can exploit this vulnerability by manipulating a specific parameter in the request, allowing them to inject arbitrary SQL queries that could retrieve email metadata.

03 Feb 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-03 20:15

Updated : 2025-06-11 21:18


NVD link : CVE-2025-25064

Mitre link : CVE-2025-25064


JSON object : View

Products Affected

synacor

  • zimbra_collaboration_suite
CWE

No CWE.