High severity8.8NVD Advisory· Published Feb 3, 2025· Updated Jun 17, 2026
CVE-2025-25064
CVE-2025-25064
Description
SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a user-supplied parameter. Authenticated attackers can exploit this vulnerability by manipulating a specific parameter in the request, allowing them to inject arbitrary SQL queries that could retrieve email metadata.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*Range: >=10.0.0,<10.0.12
- Range: 10.0.x < 10.0.12, 10.1.x < 10.1.4
Patches
Vulnerability mechanics
References
3- wiki.zimbra.com/wiki/Zimbra_Security_AdvisoriesnvdVendor Advisory
- wiki.zimbra.com/wiki/Zimbra_Releases/10.0.12nvdRelease Notes
- wiki.zimbra.com/wiki/Zimbra_Releases/10.1.4nvdRelease Notes
News mentions
0No linked articles in our index yet.