PT-2024-5574 · Roundcube+4 · Roundcube+4
Oskar Zeino-Mahmalat
·
Published
2024-06-18
·
Updated
2026-04-29
·
CVE-2024-42008
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Roundcube versions 1.5.7 and earlier, 1.6.x through 1.6.7
Description
The issue exists due to inadequate protection of the web page structure in the
rcmail action mail get->run() function of the Roundcube Webmail client. Exploitation of this issue may allow a remote attacker to conduct a cross-site scripting (XSS) attack by sending specially crafted malicious attachments. This can potentially allow the attacker to steal and send emails of a victim via a malicious email attachment served with a dangerous Content-Type header.Recommendations
For Roundcube versions 1.5.7 and earlier: Update to a version later than 1.5.7 to resolve the issue.
For Roundcube versions 1.6.x through 1.6.7: Update to a version later than 1.6.7 to resolve the issue.
As a temporary workaround, consider restricting access to the
rcmail action mail get->run() function until a patch is available. Avoid using dangerous Content-Type headers in email attachments until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Red Os
Roundcube
Ubuntu