Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2025-68645

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilt...
Back to all
CVE

CVE-2025-68645

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilt...

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
8.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://wiki.zimbra.com/wiki/SecurityCenter, https://wiki.zimbra.com/wiki/ZimbraResponsibleDisclosurePolicy, https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68645, https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68645.json, https://nvd.nist.gov/vuln/detail/CVE-2025-68645

Severity

8.8

CVSS Score
0
10

Basic Information

Base CVSS
8.8
EPSS Probability
0.49374%
EPSS Percentile
0.98806%
Introduced Version
52b539ef205db233bfd8116e8130e27735b4153c,de2f187263204c5edbcd64ab4aad155367f27eef,5a574c4741e2713147c61524e30057679ece2ec6,0da199c818c28750b27aec8c2aa1fa8420086d4e
Fix Available
1884e94c76d9602c75dff36c9ff9a5ec2224c582,2aecfa967aa09146bbab421bd09c242a420fff0e,035c4371687d035685fd572d03a55e6cabf2383c,42bcab6250f9084ac05d771550755f9401403f65

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading