CWE-CWE-22

Zimbra Collaboration LFI (CVE-2025-68645)

Severity:
High
Summary
Zimbra Collaboration contains a local file inclusion vulnerability caused by improper handling of user-supplied input in a REST servlet component. Due to insufficient validation of request parameters, an unauthenticated remote attacker can craft requests that force the application to include arbitrary files from within the web root directory.
Impact
An attacker can exploit this vulnerability to read arbitrary files from within the web root directory, potentially exposing sensitive information such as configuration files, application source code, database credentials, or other confidential data. This information disclosure could enable further attacks, including privilege escalation, unauthorized access to backend systems, or complete system compromise. The vulnerability requires no authentication and can be exploited remotely over the network.
Remediation
Upgrade Zimbra Collaboration Suite to the latest patched version and ensure all security updates are applied regularly.
Required Skills for Successful Exploitation
Actions To Take
Classifications
Vulnerability Index

You can search and find all vulnerabilities

Featured resources

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding