Junglewise Threat Intelligence

CVE-2021-44026: Roundcube Webmail SQL Injection Vulnerability

CVE-2021-44026 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-06-22

Technologies: Roundcube Webmail. Vendors: Roundcube.

Executive brief

Roundcube Webmail is vulnerable to SQL injection through the search or search_params parameters. This flaw allows a remote attacker to execute arbitrary SQL commands against the underlying database.

Affected products

  • Roundcube Roundcube Webmail before 1.3.17, 1.4.x before 1.4.12

Timeline

  • 2021-11-18: disclosed: Date based on Debian bug report 1000156 referenced in advisory
  • 2023-06-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-06-22: advisory: NVD publication date

Related threats