CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-42008

CVSS 9.3v3.1pub. 2024-08-05upd. 2025-03-13

A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.

🤖 AI Analysis
How it works

An attacker sends the victim an email containing a malicious attachment with a dangerous Content-Type header. When the victim opens or displays such an attachment in the Roundcube web interface, the vulnerable rcmail_action_mail_get->run() function improperly processes the header data, resulting in execution of malicious script in the context of the user's browser. Since the vulnerability has cross-site scope (S:C in the CVSS vector), the script can affect areas outside the original application context. Only victim interaction with the sent message is required to trigger the attack.

Impact

An attacker can hijack the victim's session, read their inbox, and send emails on their behalf without their knowledge. This results in complete loss of confidentiality and integrity of the attacked user's email correspondence.

Mitigation & patch

Roundcube Webmail should be updated to version 1.5.8 or 1.6.8, in which the vulnerability has been fixed. Patches and detailed information are available on the vendor's website (roundcube.net) and in the project's GitHub repository.

Who is affected

Roundcube Webmail in versions up to and including 1.5.7 and in versions 1.6.x up to and including 1.6.7

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Roundcube Webmail

    APP
    Roundcube
    < 1.5.81.6.0 – 1.6.8 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2025-49113CRITICAL9.9⚠ KEVPL ✓same product

RCE przez deserializację PHP w Roundcube Webmail (parametr _from)

CVE-2024-42009CRITICAL9.3⚠ KEVPL ✓same product

XSS w Roundcube Webmail umożliwiający kradzież i wysyłkę wiadomości e-mail

CVE-2021-44026CRITICAL9.8⚠ KEVPL ✓same product

SQL Injection w Roundcube Webmail via parametry wyszukiwania

CVE-2020-12641CRITICAL9.8⚠ KEVPL ✓same product

Command injection w Roundcube Webmail — RCE przez konfigurację ImageMagick

CVE-2024-37385CRITICAL9.8PL ✓same product

Command injection w Roundcube Webmail na Windows (im_convert_path/im_identify_path)