PT-2024-5574 · Roundcube+4 · Roundcube+4

Oskar Zeino-Mahmalat

·

Published

2024-06-18

·

Updated

2026-04-29

·

CVE-2024-42008

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Roundcube versions 1.5.7 and earlier, 1.6.x through 1.6.7
Description The issue exists due to inadequate protection of the web page structure in the rcmail action mail get->run() function of the Roundcube Webmail client. Exploitation of this issue may allow a remote attacker to conduct a cross-site scripting (XSS) attack by sending specially crafted malicious attachments. This can potentially allow the attacker to steal and send emails of a victim via a malicious email attachment served with a dangerous Content-Type header.
Recommendations For Roundcube versions 1.5.7 and earlier: Update to a version later than 1.5.7 to resolve the issue. For Roundcube versions 1.6.x through 1.6.7: Update to a version later than 1.6.7 to resolve the issue. As a temporary workaround, consider restricting access to the rcmail action mail get->run() function until a patch is available. Avoid using dangerous Content-Type headers in email attachments until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2025-8283
BDU:2024-06254
CVE-2024-42008
DSA-5743-1
DSA-5743-2
MGASA-2024-0279
OPENSUSE-SU-2024:0328-1
OPENSUSE-SU-2024:14243-1
USN-8223-1

Affected Products

Alt Linux
Linuxmint
Red Os
Roundcube
Ubuntu