First published: Thu Dec 19 2024(Updated: )
An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, allowing authenticated remote attackers to include and access sensitive files in the WebRoot directory. Exploitation requires a valid auth token and involves crafting a malicious request targeting specific file paths.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zimbra Collaboration Suite |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-54663 is considered a medium severity vulnerability due to its ability to allow unauthorized file access.
To fix CVE-2024-54663, upgrade to the latest patched version of Zimbra Collaboration (ZCS) that addresses this vulnerability.
CVE-2024-54663 affects Zimbra Collaboration (ZCS) versions 9.0, 10.0, and 10.1.
CVE-2024-54663 is a Local File Inclusion (LFI) vulnerability within the Webmail Classic UI.
Yes, CVE-2024-54663 can be exploited by authenticated remote attackers.