PT-2020-6404 · Roundcube+2 · Roundcube+2

Lorexxar

·

Published

2020-05-29

·

Updated

2024-03-06

·

CVE-2020-18670

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Roundcube versions prior to 4.4
Description The issue is related to a lack of protection for the web page structure, allowing a remote attacker to impact data integrity. It involves a Cross Site Scripting (XSS) issue, where an attacker can exploit the vulnerability through the database host and user in the /installer/test.php endpoint.
Recommendations For versions prior to 4.4, update to version 4.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the /installer/test.php endpoint until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2097
BDU:2021-04624
BIT-ROUNDCUBE-2020-18670
CVE-2020-18670
OPENSUSE-SU-2021:0931-1
OPENSUSE-SU-2021:0942-1
OPENSUSE-SU-2021:0943-1
OPENSUSE-SU-2021:0959-1
OPENSUSE-SU-2021:0974-1
OPENSUSE-SU-2021:1014-1
OPENSUSE-SU-2021_0931-1

Affected Products

Alt Linux
Roundcube
Suse