CVE-2025-68645, A high-severity Local File Inclusion (LFI) vulnerability, affects the Webmail Classic UI component of Zimbra Collaboration Server versions 10.0 and 10.1. The flaw is caused by improper handling of user-supplied request parameters in the RestFilter servlet, which can allow unauthenticated attackers to read arbitrary files from the server. The issue carries a high CVSS score and can expose configuration files, credentials, or other sensitive data. Disclosed file contents may be leveraged to escalate access or mount further attacks against affected deployments. Affected users are recommended to patch their vulnerable instances to versions 10.1.13, 10.0.18 or later.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.
References:

