CVE-2011-1491: Input Validation
The login form in Roundcube Webmail before 0.5.1 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then compose an e-mail message, related to a "login CSRF" issue.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1491?
CVE-2011-1491 is considered a medium severity vulnerability that can lead to unauthorized access to sensitive information.
How do I fix CVE-2011-1491?
To fix CVE-2011-1491, upgrade Roundcube Webmail to version 0.5.1 or later.
What does CVE-2011-1491 affect?
CVE-2011-1491 affects multiple versions of Roundcube Webmail prior to 0.5.1.
What type of attack is associated with CVE-2011-1491?
CVE-2011-1491 is associated with an unauthorized access vulnerability allowing remote authenticated users to expose sensitive information.
Who is affected by CVE-2011-1491?
Users of Roundcube Webmail versions prior to 0.5.1 are affected by CVE-2011-1491.