Back to Advisories
🔔 CVE Advisory

CVE-2018-20160

Zimbra Collaboration Server

ZxChat (aka ZeXtras Chat), as used for zimbra-chat and zimbra-talk in Synacor Zimbra Collaboration Suite 8.7 and 8.8 and in other products, allows XXE attacks, as demonstrated by a crafted XML request to mailboxd.

Year 2019
Published December 31, 2019

Advisory Information

Affected Product Zimbra Collaboration Server
Title CVE-2018-20160
Description

ZxChat (aka ZeXtras Chat), as used for zimbra-chat and zimbra-talk in Synacor Zimbra Collaboration Suite 8.7 and 8.8 and in other products, allows XXE attacks, as demonstrated by a crafted XML request to mailboxd.

Year 2019
Published Date December 31, 2019

Affected Vendors

Research Team