CVE-2025-68645: Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.
Other sources
Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Zimbra Collaboration Suite (ZCS)from your environment.If vendor mitigations are unavailable, discontinue use of the product and uninstall the affected Zimbra Collaboration Suite (ZCS) deployments (noted in the advisory: ZCS 10.0 and 10.1).
- Compensating control
Apply mitigations per vendor (Synacor/Zimbra) instructions. For cloud deployments, follow applicable BOD 22-01 guidance. If vendor mitigations are unavailable, take immediate mitigating measures (for example, isolate or restrict access to affected endpoints) until a vendor fix is applied or the product is removed.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68645?
CVE-2025-68645 has a high severity rating due to its potential for local file inclusion that could lead to data exposure.
How do I fix CVE-2025-68645?
To fix CVE-2025-68645, upgrade Zimbra Collaboration Suite to versions 10.1.0 or later.
What versions of Zimbra are affected by CVE-2025-68645?
CVE-2025-68645 affects Zimbra Collaboration Suite versions 10.0 and 10.1.
Can an attacker exploit CVE-2025-68645 remotely?
Yes, an unauthenticated remote attacker can exploit CVE-2025-68645 through crafted requests to the /h/rest endpoint.
What type of vulnerability is CVE-2025-68645?
CVE-2025-68645 is classified as a Local File Inclusion (LFI) vulnerability.