Junglewise Threat Intelligence

CVE-2017-16651: Roundcube Webmail File Disclosure Vulnerability

CVE-2017-16651 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Roundcube Webmail. Vendors: Roundcube.

Executive brief

Roundcube Webmail contains a file disclosure vulnerability due to insufficient input validation in file-based attachment plugins. An authenticated attacker with a valid session can exploit this to gain unauthorized access to arbitrary files on the host's filesystem, including sensitive configuration files.

Affected products

  • Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, 1.3.x before 1.3.3

Timeline

  • 2017-11-08: patched: Security updates 1.3.3, 1.2.7, and 1.1.10 released.
  • 2017-11-01: exploited: Exploitation in the wild reported to have occurred in November 2017.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats