PT-2024-5497 · Unknown+4 · Roundcube Webmail+4
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Roundcube versions prior to 1.5.8
Roundcube versions 1.6.x through 1.6.7
Description
A Cross-Site Scripting (XSS) issue exists in Roundcube Webmail due to improper sanitization in the
message body() function within the program/actions/mail/show.php file and the rcmail action mail get->run() function. A remote attacker can exploit this by sending a specially crafted email message or malicious attachments, allowing them to execute arbitrary JavaScript in the victim's browser. This can lead to the theft of credentials and the ability to send or receive emails as the victim. Real-world exploitation has been attributed to China-aligned threat actors targeting physics and engineering departments at universities in the United States and Canada for credential harvesting.Recommendations
Update Roundcube to version 1.5.8 or later.
Update Roundcube to version 1.6.8 or later.
As a temporary mitigation, restrict the use of the
message body() function or the rcmail action mail get->run() function until the software is updated.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Red Os
Roundcube Webmail
Ubuntu