CVE-2020-12640
- EPSS 20.08%
- Veröffentlicht 04.05.2020 15:15:14
- Zuletzt bearbeitet 21.11.2024 04:59:57
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
CVE-2020-12626
- EPSS 1.74%
- Veröffentlicht 04.05.2020 02:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:56
An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.
CVE-2020-12625
- EPSS 4.16%
- Veröffentlicht 04.05.2020 02:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:56
An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.
CVE-2019-15237
- EPSS 0.21%
- Veröffentlicht 20.08.2019 01:15:09
- Zuletzt bearbeitet 21.11.2024 04:28:15
Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
CVE-2019-10740
- EPSS 0.08%
- Veröffentlicht 07.04.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:19:49
In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This ...
CVE-2018-19206
- EPSS 2.45%
- Veröffentlicht 12.11.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:33
steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment.
CVE-2018-19205
- EPSS 0.32%
- Veröffentlicht 12.11.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:33
Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.
CVE-2017-17688
- EPSS 2.99%
- Veröffentlicht 16.05.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:18:27
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification ...
CVE-2018-9846
- EPSS 0.45%
- Veröffentlicht 07.04.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:47
In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plugin.move2archive request) to pe...
CVE-2018-1000071
- EPSS 0.29%
- Veröffentlicht 13.03.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:34
roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity.