NVD disclosure day

Published threat advisories for April 21, 2022

CVE advisoryKnown Exploit

CVE-2022-27926

Zimbra Collaboration Cross-Site Scripting Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Zimbra Collaboration may allow attackers to inject script or HTML via request parameters. This could impact organizations by potentially compromising data or disrupting services. The realistic business risk is that unauthorized parties could gain access to sensitive information or manipulate user int

• CISA KEV

CVE advisoryKnown Exploit

CVE-2022-27925

Zimbra Collaboration Directory Traversal Vulnerability Allows Arbitrary File Upload.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authenticated administrator using Zimbra Collaboration can exploit a file import vulnerability to upload arbitrary files. This allows for directory traversal, potentially leading to unauthorized data access and system compromise, posing a significant business risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2022-27924

Zimbra Collaboration: Arbitrary Command Injection Risk

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Zimbra Collaboration Suite is affected by a command injection vulnerability that allows unauthenticated attackers to overwrite cached data. This presents a business risk of unauthorized data modification and service disruption. Organizations should prioritize remediation to mitigate potential impacts.

• CISA KEV