PT-2024-41052 · Unknown · Roundcube Webmail
Published
2024-05-25
·
Updated
2024-05-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Roundcube Webmail versions 1.6.x
Description
The issue concerns several security problems, including cross-site scripting (XSS) vulnerabilities in handling SVG animate attributes and list columns from user preferences, as well as a command injection vulnerability via crafted im convert path/im identify path on Windows. These vulnerabilities were reported by Valentin T. and Lutz Wolf of CrowdStrike, and Huy Nguyễn Phạm Nhật.
Recommendations
For Roundcube Webmail version 1.6.x, update to the latest stable version 1.6 to resolve the issues. Before updating, ensure to backup your data.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Roundcube Webmail