Vulnerabilities
Vulnerable Software
Roundcube:  >> Webmail  >> 1.4.2  Security Vulnerabilities
CVE-2020-13965
Known exploited
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
CVSS Score
6.1
EPSS Score
0.766
Published
2020-06-09
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
CVSS Score
9.8
EPSS Score
0.067
Published
2020-05-04
CVE-2020-12641
Known exploited
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
CVSS Score
9.8
EPSS Score
0.845
Published
2020-05-04
An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.
CVSS Score
6.1
EPSS Score
0.028
Published
2020-05-04
An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.
CVSS Score
6.5
EPSS Score
0.018
Published
2020-05-04


Contact Us

Shodan ® - All rights reserved