Executive brief
Roundcube Webmail contains a file disclosure vulnerability due to insufficient input validation in file-based attachment plugins. An authenticated attacker with a valid session can exploit this to gain unauthorized access to arbitrary files on the host's filesystem, including sensitive configuration files.
Affected products
- Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, 1.3.x before 1.3.3
Timeline
- 2017-11-08: patched: Security updates 1.3.3, 1.2.7, and 1.1.10 released.
- 2017-11-01: exploited: Exploitation in the wild reported to have occurred in November 2017.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.