PT-2020-6405 · Unknown+2 · Roundcubemail+2

Published

2020-05-29

·

Updated

2024-03-06

·

CVE-2020-18671

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Roundcube Mail versions prior to 1.4.5
Description The issue is related to a Cross Site Scripting (XSS) vulnerability. It is associated with the smtp config in the installer. The vulnerability may allow a remote attacker to impact data integrity.
Recommendations For versions prior to 1.4.5, update to version 1.4.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the /installer/test.php endpoint until a patch is available. Avoid using the smtp config in the installer until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2097
ALT-PU-2020-2367
BDU:2021-04625
BIT-ROUNDCUBE-2020-18671
CVE-2020-18671
OPENSUSE-SU-2021:0931-1
OPENSUSE-SU-2021:0942-1
OPENSUSE-SU-2021:0943-1
OPENSUSE-SU-2021:0959-1
OPENSUSE-SU-2021:0974-1
OPENSUSE-SU-2021:1014-1
OPENSUSE-SU-2021_0931-1

Affected Products

Alt Linux
Roundcubemail
Suse