mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
| Software | From | Fixed in |
|---|---|---|
| synacor / zimbra_collaboration_suite | 8.7.11-p1 | 8.7.11-p1.x |
| synacor / zimbra_collaboration_suite | 8.7.11-p2 | 8.7.11-p2.x |
| synacor / zimbra_collaboration_suite | 8.7.11-p3 | 8.7.11-p3.x |
| synacor / zimbra_collaboration_suite | 8.7.11-p4 | 8.7.11-p4.x |
| synacor / zimbra_collaboration_suite | 8.7.11-p5 | 8.7.11-p5.x |
| synacor / zimbra_collaboration_suite | 8.7.11-p6 | 8.7.11-p6.x |
| synacor / zimbra_collaboration_suite | 8.7.11-p7 | 8.7.11-p7.x |
| synacor / zimbra_collaboration_suite | 8.7.11-p8 | 8.7.11-p8.x |
| synacor / zimbra_collaboration_suite | 8.7.11-p9 | 8.7.11-p9.x |
| synacor / zimbra_collaboration_suite | 8.7.11 | 8.7.11.x |
| synacor / zimbra_collaboration_suite | 8.7.0 | 8.7.11 |