cvedb.io
CVE-2022-45912
HIGH · CVSS 7.2
EPSS exploitation probability: 0%
Published 2022-12-05T22:15:11.227 · Last modified 2026-06-17T05:10:58.950

Summary

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. Remote code execution can occur through ClientUploader by an authenticated admin user. An authenticated admin user can upload files through the ClientUploader utility, and traverse to any other directory for remote code execution.

Affected products

zimbra — collaboration

Does this affect you?

Add your gear to cvedb and we'll alert you only when zimbra ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.