CVE-2020-12846
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Zimbra before 8.8.15 Patch 10 and 9.x before 9.0.0 Patch 3 allows remote code execution via an avatar file. There is potential abuse of /service/upload servlet in the webmail subsystem. A user can upload executable files (exe,sh,bat,jar) in the Contact section of the mailbox as an avatar image for a contact. A user will receive a "Corrupt File" error, but the file is still uploaded and stored locally in /opt/zimbra/data/tmp/upload/, leaving it open to possible remote execution.
Zimbra versiones anteriores a 8.8.15 Patch 10 y versiones 9.x anteriores a 9.0.0 Patch 3, permite una ejecución de código remota por medio de un archivo de avatar. Se presenta un posible abuso del servlet /service/upload en el subsistema del correo web. Un usuario puede cargar archivos ejecutables (exe, sh, bat, jar) en la sección Contact del buzón de correo como una imagen de avatar para un contacto. Un usuario recibirá un error de "Corrupt File", pero el archivo aún se carga y es almacenado localmente en /opt/zimbra/data/tmp/upload/, dejándolo abierto para una posible ejecución remota.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-05-14 CVE Reserved
- 2020-06-03 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://wiki.zimbra.com/wiki/Security_Center | 2020-06-05 | |
https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P3 | 2020-06-05 | |
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | 2020-06-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | < 8.8.15 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version " < 8.8.15" | - |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 8.8.15 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "8.8.15" | - |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 8.8.15 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "8.8.15" | p1 |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 8.8.15 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "8.8.15" | p2 |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 8.8.15 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "8.8.15" | p3 |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 8.8.15 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "8.8.15" | p4 |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 8.8.15 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "8.8.15" | p5 |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 8.8.15 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "8.8.15" | p6 |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 8.8.15 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "8.8.15" | p7 |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 8.8.15 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "8.8.15" | p8 |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 8.8.15 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "8.8.15" | p9 |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 9.0.0 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "9.0.0" | - |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 9.0.0 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "9.0.0" | p1 |
Affected
| ||||||
Synacor Search vendor "Synacor" | Zimbra Collaboration Suite Search vendor "Synacor" for product "Zimbra Collaboration Suite" | 9.0.0 Search vendor "Synacor" for product "Zimbra Collaboration Suite" and version "9.0.0" | p2 |
Affected
|