Roundcube Webmail Multiple Cross Site Request Forgery Vulnerabilities
BID:71909
Info
Roundcube Webmail Multiple Cross Site Request Forgery Vulnerabilities
| Bugtraq ID: | 71909 |
| Class: | Design Error |
| CVE: |
CVE-2014-9587 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2015 12:00AM |
| Updated: | Mar 19 2015 09:26AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Roundcube Webmail 0.5.1 Roundcube Webmail 0.5 Roundcube Webmail 0.4 Roundcube Webmail 0.3 Roundcube Webmail 0.2.1 Roundcube Webmail 0.2 Roundcube Webmail 0.1 |
| Not Vulnerable: | |
Discussion
Roundcube Webmail Multiple Cross Site Request Forgery Vulnerabilities
Roundcube Webmail is prone to multiple cross-site request-forgery vulnerabilities because it fails to properly validate HTTP requests.
An attacker can exploit these issues to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
Versions prior to Roundcube Webmail 1.0.4 are vulnerable.
Roundcube Webmail is prone to multiple cross-site request-forgery vulnerabilities because it fails to properly validate HTTP requests.
An attacker can exploit these issues to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
Versions prior to Roundcube Webmail 1.0.4 are vulnerable.
Exploit / POC
Roundcube Webmail Multiple Cross Site Request Forgery Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Roundcube Webmail Multiple Cross Site Request Forgery Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Roundcube Webmail Multiple Cross Site Request Forgery Vulnerabilities
References:
References:
- Bug 1179780 - roundcubemail: possible CSRF attacks (Red Hat)
- Bug 534766 -
(Gentoo) - Fix bugs where CSRF attacks were still possible on some requests (Roundcube)
- Roundcube Homepage (Roundcube)
- Update 1.0.4 released (Roundcube)