RoundCube Webmail Cross Site Scripting Vulnerability
BID:57849
Info
RoundCube Webmail Cross Site Scripting Vulnerability
| Bugtraq ID: | 57849 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-6121 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 07 2013 12:00AM |
| Updated: | Mar 19 2015 08:28AM |
| Credit: | Enrique Rando |
| Vulnerable: |
Red Hat Fedora 17 |
| Not Vulnerable: | |
Discussion
RoundCube Webmail Cross Site Scripting Vulnerability
RoundCube Webmail is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
RoundCube Webmail 0.8.4 is vulnerable; other versions may also be affected.
RoundCube Webmail is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
RoundCube Webmail 0.8.4 is vulnerable; other versions may also be affected.
Exploit / POC
RoundCube Webmail Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
RoundCube Webmail Cross Site Scripting Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
RoundCube Webmail Cross Site Scripting Vulnerability
References:
References:
- Fix XSS vulnerability in vbscript: and data:text links handling (GitHub Inc.)
- Project News for Roundcube Webmail (SourceForge)
- Roundcube Homepage (Roundcube)
- RoundCube Webmail Changelog (Edgewall Software)