mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
https://www.ncsc.gov.uk/files/Advisory-further-TTPs-associated-with-SVR-cyber-actors.pdf
https://www.ncsc.gov.uk/files/Advisory-APT29-targets-COVID-19-vaccine-development-V1-1.pdf
https://github.com/Nan-Hack-371/Intern-in-Vulncure
https://github.com/0xget/cve-2001-1473
https://github.com/oppsec/zaber
https://github.com/attackgithub/Zimbra-RCE
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-9670
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
https://isc.sans.edu/forums/diary/CVE20199670+Zimbra+Collaboration+Suite+XXE+vulnerability/27570/