Loading HuntDB...

RoundCube Webmail Cross-Site Scripting Vulnerability

Added June 9, 2025 Due June 30, 2025 CVE-2024-42009
On Track Roundcube / Webmail CWE-79

Description

RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.

Required Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

References

Additional Information

Catalog Version
2025.06.09
Catalog Released
June 9, 2025
Days Until Due
16 days
Last Updated
4 days, 16 hours ago