Impact
The vulnerability is a path traversal flaw in the Zimbra Briefcase document editing feature caused by improper validation of the packages parameter. An authenticated user can craft a traversal sequence, gaining read access to files outside the intended container. The weakness is classified as CWE‑24 (Improper Restriction of Operations within the File System). The impact is limited to unauthorized file disclosure rather than arbitrary code execution or denial of service, reflected in the CVSS score of 3.1.
Affected Systems
The affected product is the Zimbra Collaboration Server (ZCS). Versions prior to 10.1.17 contain the flaw; later releases contain the fix. No specific sub‑versions are listed beyond this cutoff.
Risk and Exploitability
Given the CVSS of 3.1, the overall severity is low. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a modest threat level. However, because the attack requires authentication and targets privileged users, internal actors or compromised accounts could leverage it to exfiltrate confidential data. The risk remains mitigated by applying the available update, with residual risk if the patch cannot be deployed promptly.
OpenCVE Enrichment