When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.CreditsJonah Burgess (CryptoCat), Senior Security Researcher, Rapid7Referenceshttps://wiki.zimbra.com/wiki/Zimbra_Security_Advisories