Zimbra has released software updates to address critical security flaws in its Collaboration software that, if successfully exploited, could result in information disclosure under certain conditions. The vulnerability, tracked as CVE-2025-25064, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as an SQL injection bug in the ZimbraSync Service SOAP endpoint affecting
![]()
source https://thehackernews.com/2025/02/zimbra-releases-security-updates-for.html
source https://thehackernews.com/2025/02/zimbra-releases-security-updates-for.html