zimbra-attack

Installation
SKILL.md

Zimbra Attack Skill

Zimbra Collaboration Suite attack surface — SOAP API user enumeration without authentication, version fingerprinting, UploadServlet path traversal (CVE-2022-37042), /service/proxy internal SSRF, and Admin console access. Confirmed on IGN Argentina (Zimbra 8.8.11, admin user confirmed, UploadServlet active), gov-finance-portal (Zimbra webmail, SOAP auth functional), and ITERJ (Zimbra webmail active).

When to Use

  • Target has webmail., mail., or zimbra. subdomains.
  • Redirect to /zimbra/ path on mail server.
  • Server header or page title contains "Zimbra".
  • After subdomain-enumeration discovers webmail hosts.
  • Government, university, or enterprise targets (Zimbra is common in these sectors).

Prerequisites

  • terminal with curl, python3.
  • Target Zimbra URL (typically https://webmail.target.com).
  • For CVE exploitation: knowledge of target Zimbra version.

How to Run

Installs
11
GitHub Stars
1.2K
First Seen
Jul 9, 2026
zimbra-attack — uphiago/recon-skills