An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, allowing authenticated remote attackers to include and access sensitive files in the WebRoot directory. Exploitation requires a valid auth token and involves crafting a malicious request targeting specific file paths.
                
            References
                    | Link | Resource | 
|---|---|
| https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.11#Security_Fixes | Release Notes | 
| https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.3#Security_Fixes | Release Notes | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    11 Jun 2025, 21:17
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:* | |
| References | () https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.11#Security_Fixes - Release Notes | |
| References | () https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.3#Security_Fixes - Release Notes | |
| First Time | Synacor Synacor zimbra Collaboration Suite | 
31 Dec 2024, 19:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 7.5 | 
| CWE | CWE-829 | |
| Summary | 
 | 
19 Dec 2024, 23:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-12-19 23:15
Updated : 2025-06-11 21:17
NVD link : CVE-2024-54663
Mitre link : CVE-2024-54663
CVE.ORG link : CVE-2024-54663
JSON object : View
Products Affected
                synacor
- zimbra_collaboration_suite
CWE
                
                    
                        
                        CWE-829
                        
            Inclusion of Functionality from Untrusted Control Sphere
