CVE-2009-4077: CSRF
Published Nov 25, 2009
·Updated
Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that send arbitrary emails via unspecified vectors, a different vulnerability than CVE-2009-4076.
Affected Software
18 affected components
Roundcube Webmail<=0.2.2
Roundcube Webmail=0.1
Roundcube Webmail=0.1-20050811
Roundcube Webmail=0.1-20050820
Roundcube Webmail=0.1-20051007
Roundcube Webmail=0.1-20051021
Roundcube Webmail=0.1-alpha
Roundcube Webmail=0.1-beta
Roundcube Webmail=0.1-beta2
Roundcube Webmail=0.1-rc1
Roundcube Webmail=0.1-rc2
Roundcube Webmail=0.1-stable
Roundcube Webmail=0.1.1
Roundcube Webmail=0.2
Roundcube Webmail=0.2-alpha
Roundcube Webmail=0.2-beta
Roundcube Webmail=0.2-stable
Roundcube Webmail=0.2.1
Event History
Nov 25, 2009
CVE Published
via MITRE·09:22 PM
Data Sourced
via MITRE·09:22 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-4077?
CVE-2009-4077 is considered a high-severity cross-site request forgery (CSRF) vulnerability.
2
How do I fix CVE-2009-4077?
To fix CVE-2009-4077, you should upgrade Roundcube Webmail to a version later than 0.2.2.
3
Who is affected by CVE-2009-4077?
CVE-2009-4077 affects users of Roundcube Webmail version 0.2.2 and earlier.
4
What types of attacks are possible with CVE-2009-4077?
CVE-2009-4077 allows attackers to hijack user authentication and send arbitrary emails.
5
Is CVE-2009-4077 related to any other vulnerabilities?
CVE-2009-4077 is related to but distinct from CVE-2009-4076.