An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. Remote code execution can occur through ClientUploader by an authenticated admin user. An authenticated admin user can upload files through the ClientUploader utility, and traverse to any other directory for remote code execution.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-12-05T00:00:00

Updated: 2022-12-05T00:00:00

Reserved: 2022-11-26T00:00:00


Link: CVE-2022-45912

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-12-05T22:15:11.227

Modified: 2022-12-08T13:45:44.077


Link: CVE-2022-45912

JSON object: View

cve-icon Redhat Information

No data.

CWE