CVE-2025-25064

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-25064
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-25064.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-25064
Published
2025-02-03T20:15:37Z
Modified
2025-06-12T11:02:23.904309Z
Summary
[none]
Details

SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a user-supplied parameter. Authenticated attackers can exploit this vulnerability by manipulating a specific parameter in the request, allowing them to inject arbitrary SQL queries that could retrieve email metadata.

References

Affected packages

Git / github.com/zimbra/zm-build

Affected ranges

Type
GIT
Repo
https://github.com/zimbra/zm-build
Events
Type
GIT
Repo
https://github.com/zimbra/zm-mailbox
Events
Type
GIT
Repo
https://github.com/zimbra/zm-zcs-lib
Events

Affected versions

10.*

10.0.0-GA
10.0.1
10.0.11
10.0.2
10.0.5
10.0.6
10.0.7
10.0.8
10.0.9
10.1.0
10.1.1