PT-2018-19070 · Roundcube+2 · Roundcube+2

Andrea Basile

·

Published

2018-04-07

·

Updated

2026-03-30

·

CVE-2018-9846

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Roundcube versions 1.2.0 through 1.3.5
Description The issue allows for an IMAP injection attack by exploiting the unsanitized " uid" parameter in an archive.php request, specifically when the task=mail& mbox=INBOX& action=plugin.move2archive endpoint is used. This can be achieved by placing an IMAP command after a %0d%0a sequence. It's noted that versions 1.3.4 and later have a reduced exploitability due to a Same Origin Policy protection mechanism.
Recommendations For versions 1.2.0 through 1.3.5, consider disabling the archive plugin until a patch is available to prevent exploitation of the " uid" parameter in the archive.php request. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1778
CVE-2018-9846
DSA-4181-1
MGASA-2018-0288
OPENSUSE-SU-2024:11303-1
USN-8132-1

Affected Products

Alt Linux
Roundcube
Ubuntu