
Defender-focused reference pack for CVE-2025-68645 Zimbra LFI, including Sigma/Splunk detection rules, WAF mitigation snippets, IOC patterns, and internal advisory for incident response.
This repository is a defender-focused reference pack for CVE-2025-68645, a Local File Inclusion (LFI) issue in
Zimbra Collaboration (ZCS) 10.0.x and 10.1.x Classic Webmail UI caused by improper handling of user-controlled
request parameters in the RestFilter servlet.
javax.servlet.include.servlet_path⚠️ This repo intentionally does not include exploit code, weaponized proof-of-concepts, or targeting guidance.
detection/).This content is provided for defensive security purposes only.