CVE-2013-7091 is a directory traversal vulnerability affecting Zimbra Collaboration Suite versions 7.2.2 and 8.0.2. This flaw allows remote attackers to read arbitrary files by manipulating the skin parameter in specific JavaScript files. While the direct impact is information disclosure, it can be escalated to arbitrary code execution by obtaining LDAP credentials and accessing the service/admin/soap API. The vulnerability has a CVSS score of 5.0 and an exceptionally high EPSS score of 0.93748, indicating a significant likelihood of exploitation. Multiple public exploits exist, including Metasploit modules and Nuclei templates, and it has garnered community discussion and media coverage, suggesting active awareness and potential exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0.0CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:6.0.0:*:*:*:*:*:*:* | ||
6.0.1CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:6.0.1:*:*:*:*:*:*:* | ||
6.0.2CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:6.0.2:*:*:*:*:*:*:* | ||
6.0.3CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:6.0.3:*:*:*:*:*:*:* | ||
6.0.4CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:6.0.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.