CVE•Published 2022-04-21•Modified 2026-10-01•3 articles on news•6 live references•NVD data
CVE-2022-27925Synacor · Zimbra_collaboration_suite
Vulnerability data via NVD (ingested)
CVSS v3.1
7.2
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS percentile
100
Exploit Prediction Scoring System · top 0% of all CVEs
Weaknesses (CWE)
Description
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
Timeline
Published 2022-04-21
Modified 2026-10-01
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag0 hosts
vuln:CVE-2022-27925Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product + version
product:"Synacor Zimbra Collaboration Suite" version:"8.8.15"Version-pinned fingerprint from NVD's first vulnerable CPE.
Shodan · banner/body mention
http.html:"Zimbra Collaboration Suite"HTTP body or banner mentions "Zimbra Collaboration Suite" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2022-27925Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2022-27925Censys host search filtered to this CVE id.
grep.app
CVE-2022-27925Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2022-27925GitHub code search for direct mentions.
Google dork
"CVE-2022-27925" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (6)
CVE-2022-279256 repos
Mr-xn/Penetration_Testing_POCHTML
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypas…
k8gege/LadonC#
Ladon大型内网渗透扫描器,PowerShell、Cobalt Strike插件、内存加载、无文件扫描。含端口扫描、服务识别、网络资产探测、密码审计、高危漏洞检测、漏洞利用、密码读取以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描等。网络资产探测32种协议(ICMP\NBT\DNS\MAC\SMB\WMI\S…
emadshanab/Nuclei-Templates-CollectionPython
Nuclei Templates Collection
Ostorlab/KEVunknown
Ostorlab KEV: One-command to detect most remotely known exploitable vulnerabilities. Sourced from CISA KEV, Google's Tsunami, Ostorlab's Asteroid and Bug Bounty programs.
peiqiF4ck/WebFrameworkTools-5.5-enhanceC#
本软件首先集成危害性较大框架和部分主流cms的rce(无需登录,或者登录绕过执行rce)和反序列化(利用链简单)。傻瓜式导入url即可实现批量getshell。批量自动化测试。例如:Thinkphp,Struts2,weblogic。出现的最新漏洞进行实时跟踪并且更新例如:log4jRCE,向日葵 禅道RCE 瑞友天翼应用虚拟化系统sql注入导致RCE大华智…
0x7556/wolfshellASP.NET
幽狼AI Shell:首款支持AI渗透的高级WebShell & C2管理工具,内置WebShell MCP服务器,支持多层内网级联的ASPX、ASHX高级WebShell管理工具,AES加密通信,无需代理,内存加载渗透工具,无文件落地隐蔽渗透目标,动态代码执行,ShellCode加载(Metasploit/Cobalt Strike),反弹Shell,So…