CVE-2025-68645

HIGH KEV NUCLEI

Zimbra Collaboration <10.2 - LFI

Title source: llm

Description

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.

Exploits (6)

github SCANNER 40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/ZimbraCollaboration-CVE-2025-68645-localInclusion.py
nomisec TROJAN 2 stars
by chinaxploiter · poc
https://github.com/chinaxploiter/CVE-2025-68645-PoC
github SCANNER
by 0xBlackash · pythonpoc
https://github.com/0xBlackash/CVE-2025-68645
nomisec SCANNER
by CMEGh0stX47 · infoleak
https://github.com/CMEGh0stX47/CVE-2025-68645
nomisec WRITEUP
by faysalferdous · poc
https://github.com/faysalferdous/CVE-2025-68645-Exploiting-Zimbra-Webmail-LFI-Vulnerability
nomisec WRITEUP
by MaxMnMl · infoleak
https://github.com/MaxMnMl/zimbramail-CVE-2025-68645-poc

Nuclei Templates (1)

Zimbra Collaboration - Local File Inclusion
HIGHVERIFIEDby DhiyaneshDk,sirifu4k1
Shodan: http.title:"Zimbra Collaboration Suite"

Scores

CVSS v3 8.8
EPSS 0.4707
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CISA KEV 2026-01-22
VulnCheck KEV 2026-01-14
ENISA EUVD EUVD-2025-204719
CWE
CWE-98
Status published
Products (1)
synacor/zimbra_collaboration_suite 10.0.0 - 10.0.18
Published Dec 22, 2025
KEV Added Jan 22, 2026
Tracked Since Feb 18, 2026