CVE-2024-45519
KEVCRITICAL 10.0EPSS 99.9%
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS
- 99.91% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2024-10-03
- Nuclei
- critical
- Published
- 2024-10-02
- Updated
- 2026-02-03
Proof-of-concept exploits (6)
- Chocapikk/CVE-2024-45519139★ · 2025-04-06
- p33d/CVE-2024-4551942★ · 2024-09-28
- sec13b/CVE-2024-455190★ · 2025-03-08
- ark0-nights/cve_exps
- chengbochuan3/CVE-Enterprise-Software
- cleverg0d/CVEs