.. / CVE-2019-9670

Exploit for Synacor Zimbra Collaboration <8.7.11p10 - XML External Entity Injection (CVE-2019-9670)

Description:

Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML external entity injection (XXE) vulnerability via the mailboxd component.

Nuclei Template

View the template here CVE-2019-9670.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2019/CVE-2019-9670.yaml
Copy

References:

https://www.exploit-db.com/exploits/46693/
http://packetstormsecurity.com/files/152487/Zimbra-Collaboration-Autodiscover-Servlet-XXE-ProxyServlet-SSRF.html
https://bugzilla.zimbra.com/show_bug.cgi?id=109129
https://nvd.nist.gov/vuln/detail/CVE-2019-9670
https://isc.sans.edu/forums/diary/CVE20199670+Zimbra+Collaboration+Suite+XXE+vulnerability/27570/
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
http://www.rapid7.com/db/modules/exploit/linux/http/zimbra_xxe_rce