Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.
https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates
https://www.tenable.com/cyber-exposure/tenable-2022-threat-landscape-report
https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-228a
https://github.com/imthenachoman/How-To-Secure-A-Linux-Server
https://github.com/romero-javi/zimbra8_lab
https://github.com/Pr0t0c01/CVEs
https://github.com/0xf4n9x/CVE-2022-37042
https://github.com/jam620/Zimbra
https://github.com/aels/CVE-2022-37042
https://github.com/Josexv1/CVE-2022-27925
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-37042
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
https://wiki.zimbra.com/wiki/Security_Center
http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html