Executive brief
Roundcube Webmail is vulnerable to SQL injection through the search or search_params parameters. This flaw allows a remote attacker to execute arbitrary SQL commands against the underlying database.
Affected products
- Roundcube Roundcube Webmail before 1.3.17, 1.4.x before 1.4.12
Timeline
- 2021-11-18: disclosed: Date based on Debian bug report 1000156 referenced in advisory
- 2023-06-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-06-22: advisory: NVD publication date