CVE-2025-68645 is a critical Local File Inclusion (LFI) vulnerability found in the Webmail Classic UI of Zimbra Collaboration (ZCS) versions 10.0 and 10.1. This flaw allows an unauthenticated remote attacker to craft requests to the /h/rest endpoint, leveraging improper parameter handling to include arbitrary files from the WebRoot directory. With a CVSS score of 8.8 (HIGH), it poses a significant risk to confidentiality, integrity, and availability due to its low attack complexity and lack of authentication requirement. The vulnerability is actively exploited in the wild, confirmed by its inclusion in CISA's KEV catalog and extensive community discussion, with Nuclei templates publicly available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.0, < 10.0.18CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:* | ||
>= 10.1.0, < 10.1.13CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Zimbra Collaboration Suite Local File Inclusion (CVE-2025-68645)
Jan 1, 2026Zimbra Collaboration Suite Local File Inclusion (CVE-2025-68645)
Jan 1, 2026Zimbra Collaboration Suite Local File Inclusion (CVE-2025-68645)
Jan 1, 2026Zimbra Collaboration Local File Inclusion (CVE-2025-68645)
Jan 1, 2026Zimbra Collaboration Suite Local File Inclusion (CVE-2025-68645)
Jan 1, 2026