CVE-2025-68645
CISA KEV Active Alert
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.
Attack Parameters
Technical Impact
Affected Configurations
Total: 24 detected entries
Time Line
Key Metrics
Recommended Solution
Related News Articles
2 article(s) mentioning this vulnerability
CISA ajoute quatre vulnérabilités actuellement exploitées au catalogue KEV
CISA met à jour son catalogue KEV avec quatre nouvelles vulnérabilités de sécurité actuellement exploitées.
CISA Adds Four Active Exploited Software Vulnerabilities to KEV Catalog
CISA updates its Known Exploited Vulnerabilities (KEV) catalog with four new security flaws that have been actively exploited.
Immediate Action Plan
1. Inventory
Identify all affected systems in your infrastructure.
2. Assessment
Assess exposure and criticality for your organization.
3. Mitigation
Apply patches or available workarounds.
4. Verification
Test and confirm effectiveness of applied measures.
⚠️ MAXIMUM PRIORITY - Immediate action required
