CVE-2009-4076: CSRF
Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that modify user information via unspecified vectors, a different vulnerability than CVE-2009-4077.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4076?
CVE-2009-4076 is considered a medium severity vulnerability due to its potential to allow unauthorized actions on behalf of users.
How do I fix CVE-2009-4076?
To fix CVE-2009-4076, users should upgrade to Roundcube Webmail versions higher than 0.2.2 or apply available patches.
What systems are affected by CVE-2009-4076?
CVE-2009-4076 affects Roundcube Webmail versions 0.2.2 and earlier, including various release candidates and beta versions.
What type of vulnerability is CVE-2009-4076?
CVE-2009-4076 is a cross-site request forgery (CSRF) vulnerability that can be exploited to hijack user authentication.
Can I test for CVE-2009-4076 in my environment?
Yes, you can test for CVE-2009-4076 by checking for the affected versions of Roundcube Webmail and attempting to exploit the CSRF vector.