PT-2024-5497 · Unknown+4 · Roundcube Webmail+4

·

CVE-2024-42009

·

Published

2024-06-18

·

Updated

2026-07-24

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Roundcube versions prior to 1.5.8 Roundcube versions 1.6.x through 1.6.7
Description A Cross-Site Scripting (XSS) issue exists in Roundcube Webmail due to improper sanitization in the message body() function within the program/actions/mail/show.php file and the rcmail action mail get->run() function. A remote attacker can exploit this by sending a specially crafted email message or malicious attachments, allowing them to execute arbitrary JavaScript in the victim's browser. This can lead to the theft of credentials and the ability to send or receive emails as the victim. Real-world exploitation has been attributed to China-aligned threat actors targeting physics and engineering departments at universities in the United States and Canada for credential harvesting.
Recommendations Update Roundcube to version 1.5.8 or later. Update Roundcube to version 1.6.8 or later. As a temporary mitigation, restrict the use of the message body() function or the rcmail action mail get->run() function until the software is updated.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-8283
BDU:2024-06146
BDU:2024-06254
CVE-2024-42009
DSA-5743-1
DSA-5743-2
MGASA-2024-0279
OPENSUSE-SU-2024:0328-1
OPENSUSE-SU-2024:14243-1
USN-7636-1

Affected Products

Alt Linux
Linuxmint
Red Os
Roundcube Webmail
Ubuntu