CVE-2025-25064: SQL Injection
SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a user-supplied parameter. Authenticated attackers can exploit this vulnerability by manipulating a specific parameter in the request, allowing them to inject arbitrary SQL queries that could retrieve email metadata.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25064?
CVE-2025-25064 is considered a critical vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2025-25064?
To fix CVE-2025-25064, upgrade Zimbra Collaboration to version 10.0.12 or 10.1.4 or later.
Which versions of Zimbra Collaboration are affected by CVE-2025-25064?
CVE-2025-25064 affects Zimbra Collaboration versions 10.0.x before 10.0.12 and 10.1.x before 10.1.4.
What type of vulnerability is CVE-2025-25064?
CVE-2025-25064 is an SQL injection vulnerability found in the ZimbraSyncService SOAP endpoint.
What are the potential impacts of exploiting CVE-2025-25064?
Exploiting CVE-2025-25064 could allow an attacker to execute arbitrary SQL queries and potentially compromise sensitive data.