PT-2018-19070 · Roundcube+2 · Roundcube+2
Andrea Basile
·
Published
2018-04-07
·
Updated
2026-03-30
·
CVE-2018-9846
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Roundcube versions 1.2.0 through 1.3.5
Description
The issue allows for an IMAP injection attack by exploiting the unsanitized
" uid" parameter in an archive.php request, specifically when the task=mail& mbox=INBOX& action=plugin.move2archive endpoint is used. This can be achieved by placing an IMAP command after a %0d%0a sequence. It's noted that versions 1.3.4 and later have a reduced exploitability due to a Same Origin Policy protection mechanism.Recommendations
For versions 1.2.0 through 1.3.5, consider disabling the archive plugin until a patch is available to prevent exploitation of the
" uid" parameter in the archive.php request.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Roundcube
Ubuntu