A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.
An attacker sends the victim an email containing a malicious attachment with a dangerous Content-Type header. When the victim opens or displays such an attachment in the Roundcube web interface, the vulnerable rcmail_action_mail_get->run() function improperly processes the header data, resulting in execution of malicious script in the context of the user's browser. Since the vulnerability has cross-site scope (S:C in the CVSS vector), the script can affect areas outside the original application context. Only victim interaction with the sent message is required to trigger the attack.
An attacker can hijack the victim's session, read their inbox, and send emails on their behalf without their knowledge. This results in complete loss of confidentiality and integrity of the attacked user's email correspondence.
Roundcube Webmail should be updated to version 1.5.8 or 1.6.8, in which the vulnerability has been fixed. Patches and detailed information are available on the vendor's website (roundcube.net) and in the project's GitHub repository.
Roundcube Webmail in versions up to and including 1.5.7 and in versions 1.6.x up to and including 1.6.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NRoundcube Webmail
APPRoundcube< 1.5.81.6.0 – 1.6.8 (excl.)
Related vulnerabilities
RCE przez deserializację PHP w Roundcube Webmail (parametr _from)
XSS w Roundcube Webmail umożliwiający kradzież i wysyłkę wiadomości e-mail
SQL Injection w Roundcube Webmail via parametry wyszukiwania
Command injection w Roundcube Webmail — RCE przez konfigurację ImageMagick
Command injection w Roundcube Webmail na Windows (im_convert_path/im_identify_path)