Reads internal configuration files like WEB-INF/web.xml without authentication through Zimbra's RestFilter servlet path parameter.
Is your app exploitable through CVE-2025-68645?