Critical severity9.8CISA KEVNVD Advisory· Published May 29, 2019· Updated Jun 17, 2026
CVE-2019-9670
CVE-2019-9670
Description
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*range: >=8.7.0,<8.7.11
- cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:-:*:*:*:*:*:*
- cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p1:*:*:*:*:*:*
- cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p2:*:*:*:*:*:*
- cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p3:*:*:*:*:*:*
- cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p4:*:*:*:*:*:*
- cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p5:*:*:*:*:*:*
- cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p6:*:*:*:*:*:*
- cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p7:*:*:*:*:*:*
- cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p8:*:*:*:*:*:*
- cpe:2.3:a:synacor:zimbra_collaboration_suite:8.7.11:p9:*:*:*:*:*:*
- Synacor/Zimbra Collaboration Suitedescription
- Range: <8.7.11p10
Patches
Vulnerability mechanics
References
7- bugzilla.zimbra.com/show_bug.cginvdBroken LinkIssue TrackingPatchThird Party Advisory
- packetstormsecurity.com/files/152487/Zimbra-Collaboration-Autodiscover-Servlet-XXE-ProxyServlet-SSRF.htmlnvdExploitThird Party AdvisoryVDB Entry
- isc.sans.edu/forums/diary/CVE20199670+Zimbra+Collaboration+Suite+XXE+vulnerability/27570/nvdExploitThird Party Advisory
- www.exploit-db.com/exploits/46693/nvdExploitThird Party AdvisoryVDB Entry
- www.rapid7.com/db/modules/exploit/linux/http/zimbra_xxe_rcenvdThird Party Advisory
- wiki.zimbra.com/wiki/Zimbra_Security_AdvisoriesnvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.