PT-2023-23662 · Roundcube · Roundcube Password Recovery Plugin
Pedro José Navas Pérez
·
Published
2023-09-04
·
Updated
2023-09-08
·
CVE-2023-3221
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Roundcube Password Recovery plugin version 1.2
Description
The issue allows a remote attacker to create a test script against the password recovery function to enumerate all users in the database. This is a user enumeration vulnerability in the Password Recovery plugin for Roundcube.
Recommendations
For Roundcube Password Recovery plugin version 1.2, consider disabling the password recovery function until a patch is available to prevent user enumeration. Restrict access to the password recovery module to minimize the risk of exploitation. Avoid using the password recovery feature in the affected plugin until the issue is resolved.
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Roundcube Password Recovery Plugin