Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-25064

SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a user-supplied parameter. Authenticated attackers can exploit this vulnerability by manipulating a specific parameter in the request, allowing them to inject arbitrary SQL queries that could retrieve email metadata.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.202
EPSS Ranking 95.2%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2025-25064


Contact Us

Shodan ® - All rights reserved