{"id":"CVE-2025-68645","details":"A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.","modified":"2026-03-03T01:23:36.267599Z","published":"2025-12-22T18:16:17.070Z","references":[{"type":"WEB","url":"https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68645"},{"type":"ADVISORY","url":"https://wiki.zimbra.com/wiki/Security_Center"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-build","events":[{"introduced":"52b539ef205db233bfd8116e8130e27735b4153c"},{"fixed":"1884e94c76d9602c75dff36c9ff9a5ec2224c582"},{"introduced":"b68c7b31a1d94f94903a79c53f1bd316b792de1d"},{"fixed":"c2fac09a3333bcb767866afa3203541da2e8729c"}]}],"versions":["10.1.0","10.1.1","10.1.10","10.1.4","10.1.5","10.1.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68645.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-mailbox","events":[{"introduced":"8033bd1ec9d7211c2eb5fa71aeb3b4073a8dc160"},{"fixed":"6f001741160336733794f909939fcb0b9e59f107"},{"introduced":"de2f187263204c5edbcd64ab4aad155367f27eef"},{"fixed":"2aecfa967aa09146bbab421bd09c242a420fff0e"}]}],"versions":["10.0.0-GA","10.1.0","10.1.1","10.1.10","10.1.2","10.1.3","10.1.4","10.1.5","10.1.6","10.1.7","10.1.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68645.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-zcs","events":[{"introduced":"5a574c4741e2713147c61524e30057679ece2ec6"},{"fixed":"035c4371687d035685fd572d03a55e6cabf2383c"}]}],"versions":["10.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68645.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-zcs-lib","events":[{"introduced":"0da199c818c28750b27aec8c2aa1fa8420086d4e"},{"fixed":"42bcab6250f9084ac05d771550755f9401403f65"},{"introduced":"e94be3228495cb215d7bb70d6ae24bc8a42cc01f"},{"fixed":"f84684c7abd7ba2681e64499bf54719c764565e1"}]}],"versions":["10.0.0-GA","10.0.1","10.0.12","10.0.9","10.1.0","10.1.1","10.1.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68645.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}