CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2024-42009

CVSS 9.3v3.1pub. 2024-08-05upd. 2025-11-04

A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.

🤖 AI Analysis
How it works

An attacker sends a specially crafted email message to the victim. When this message is displayed in the Roundcube client, a desanitization error occurs in the message_body() function located in the program/actions/mail/show.php file. As a result, malicious JavaScript code embedded in the message is executed in the victim's browser in the context of the webmail application, allowing the attacker to take control of the user's session and email operations.

Impact

An attacker can read the victim's private emails and send messages on their behalf, leading to serious breach of confidentiality and integrity of correspondence. The impact may also include further attacks based on compromised credentials or information contained in the mailbox.

Mitigation & patch

Roundcube Webmail should be immediately updated to version 1.5.8 or 1.6.8, in which the vendor has made security patches available. Patches are available in vendor references: https://roundcube.net/news/2024/08/04/security-updates-1.6.8-and-1.5.8

Who is affected

Roundcube Webmail in versions up to and including 1.5.7 and versions 1.6.x up to and including 1.6.7

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Roundcube Webmail

    APP
    Roundcube
    < 1.5.81.6.0 – 1.6.8 (excl.)

CISA KEV — detailsi

Vendori
Roundcube
Producti
Webmail
Added to KEVi
June 9, 2025
Remediation deadline (US Federal)i
June 30, 2025(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 30 czerwca 2025
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2025-49113CRITICAL9.9⚠ KEVPL ✓same product

RCE przez deserializację PHP w Roundcube Webmail (parametr _from)

CVE-2021-44026CRITICAL9.8⚠ KEVPL ✓same product

SQL Injection w Roundcube Webmail via parametry wyszukiwania

CVE-2020-12641CRITICAL9.8⚠ KEVPL ✓same product

Command injection w Roundcube Webmail — RCE przez konfigurację ImageMagick

CVE-2024-42008CRITICAL9.3PL ✓same product

XSS w Roundcube Webmail umożliwiający kradzież i wysyłkę e-maili ofiary

CVE-2024-37385CRITICAL9.8PL ✓same product

Command injection w Roundcube Webmail na Windows (im_convert_path/im_identify_path)