CVE-2024-54663: High severity zimbra collaboration suite vulnerability
An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, allowing authenticated remote attackers to include and access sensitive files in the WebRoot directory. Exploitation requires a valid auth token and involves crafting a malicious request targeting specific file paths.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54663?
CVE-2024-54663 is considered a medium severity vulnerability due to its ability to allow unauthorized file access.
How do I fix CVE-2024-54663?
To fix CVE-2024-54663, upgrade to the latest patched version of Zimbra Collaboration (ZCS) that addresses this vulnerability.
Which versions of Zimbra Collaboration are affected by CVE-2024-54663?
CVE-2024-54663 affects Zimbra Collaboration (ZCS) versions 9.0, 10.0, and 10.1.
What type of vulnerability is CVE-2024-54663?
CVE-2024-54663 is a Local File Inclusion (LFI) vulnerability within the Webmail Classic UI.
Can CVE-2024-54663 be exploited remotely?
Yes, CVE-2024-54663 can be exploited by authenticated remote attackers.