Vulnerabilities
Vulnerable Software
Roundcube:  >> Webmail  >> 1.2.3  Security Vulnerabilities
Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.
CVSS Score
8.8
EPSS Score
0.006
Published
2017-04-29
rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element.
CVSS Score
6.1
EPSS Score
0.006
Published
2017-03-12


Contact Us

Shodan ® - All rights reserved