First published: Mon Feb 03 2025(Updated: )
SQL injection vulnerability in the ZimbraSyncService SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zimbra Collaboration | <10.0.12<10.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25064 is considered a critical vulnerability due to its potential for SQL injection attacks.
To fix CVE-2025-25064, upgrade Zimbra Collaboration to version 10.0.12 or 10.1.4 or later.
CVE-2025-25064 affects Zimbra Collaboration versions 10.0.x before 10.0.12 and 10.1.x before 10.1.4.
CVE-2025-25064 is an SQL injection vulnerability found in the ZimbraSyncService SOAP endpoint.
Exploiting CVE-2025-25064 could allow an attacker to execute arbitrary SQL queries and potentially compromise sensitive data.