Cve20207796 Zimbra Collaboration Suite [cracked] Full
The servlet is supposed to restrict paths to within the Zimbra installation directory. However, due to insufficient sanitization, an attacker could supply a path with directory traversal ( ../ ) or inject command delimiters.
CVE-2020-7796 is a Server-Side Request Forgery (SSRF) vulnerability in the Zimbra Collaboration Suite (ZCS) . Vulnerability Details Severity : Critical (CVSS Score: 9.8 ). cve20207796 zimbra collaboration suite full
While the vulnerability was first identified in 2020, it remains a major threat. , citing active exploitation in the wild. Organizations were given a due date of March 10, 2026, to apply mitigations. Affected Versions The servlet is supposed to restrict paths to