UBUNTU-CVE-2025-8264

Source
https://ubuntu.com/security/CVE-2025-8264
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-8264.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2025-8264
Upstream
Published
2025-07-29T05:15:00Z
Modified
2025-07-31T05:07:36Z
Severity
  • 9.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
  • 7.9 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:P CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attacker can inject malicious commands by manipulating the username field in basic authentication. This allows the attacker to access and potentially modify or delete sensitive data from a linked third-party database. Note: This vulnerability affects Z-Push installations that utilize the IMAP backend and have the IMAPFROMSQLQUERY option configured. Mitigation Change configuration to use the default or LDAP in backend/imap/config.php php define('IMAPDEFAULTFROM', ''); or php define('IMAP_DEFAULTFROM', 'ldap');

References

Affected packages

Ubuntu:Pro:18.04:LTS / z-push

Package

Name
z-push
Purl
pkg:deb/ubuntu/z-push@2.3.8-2ubuntu1?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.3.8-2ubuntu1

Ubuntu:Pro:20.04:LTS / z-push

Package

Name
z-push
Purl
pkg:deb/ubuntu/z-push@2.5.1-1?arch=source&distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.5.1-1

Ubuntu:22.04:LTS / z-push

Package

Name
z-push
Purl
pkg:deb/ubuntu/z-push@2.6.0-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.6.0-1