CVE-2013-7091: Synacor Zimbra Collaboration Suite

Medium severity, CVSS 5.0. EPSS: 86.3% chance of exploitation in the next 30 days.

Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter. NOTE: this can be leveraged to execute arbitrary code by obtaining LDAP credentials and accessing the service/admin/soap API.

Affected products

  • Synacor Zimbra Collaboration Suite: version 6.0.0 only; version 6.0.1 only; version 6.0.2 only; version 6.0.3 only; version 6.0.4 only; version 6.0.5 only; …

Published 2013-12-13. Last modified 2026-06-17.