Authentication Bypass in MailboxImportServlet vulnerability (reminder)
https://blog.zimbra.com/2022/08/authentication-bypass-in-mailboximportservlet-vulnerability/

Alternative for port 7071 for admin actions like importing contacts

Have a great idea for extending Zimbra? Share ideas, ask questions, contribute, and get feedback.
ZimbraInd
Posts: 1
Joined: Wed Sep 21, 2022 5:50 pm

Alternative for port 7071 for admin actions like importing contacts

Postby ZimbraInd » Wed Sep 21, 2022 6:00 pm

Hi,

I'm very new to Zimbra and have been working on creating ways for applications to import mails and contacts to user mailboxes.

For the same i explored the usage of rest apis, and was able to as an admin import mails (.msg files) into user mailbox. Used the endpoint: https://myzimbraserver.com:7071/home/ad ... m/contacts
However I don't want to exposing the port to 7071.

I also see that I can use the endpoint: https://myzimbraserver.com/home/zimbrau ... rset=UTF-8
This uses user credentials.

Is there any other similar way to import mails/contacts into zimbra user mailboxes which can be done via admin creds? Or is it the case that for using admin creds port 7071 is the only option?

Requesting the guidance of the community


Return to “Developers”

Who is online

Users browsing this forum: No registered users and 2 guests