CVE-2013-6172: SQL Injection
steps/utils/savepref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the session parameter, which can be leveraged to read arbitrary files, conduct SQL injection attacks, and execute arbitrary code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
roundcube webmailto a version that resolves this vulnerability.Fixed in 0.8.7 - Upgrade
Upgrade
roundcube webmailto a version that resolves this vulnerability.Fixed in 0.9.5
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6172?
CVE-2013-6172 has been classified as a high severity vulnerability due to its potential to allow unauthorized configuration modifications and code execution.
How do I fix CVE-2013-6172?
To fix CVE-2013-6172, you should upgrade Roundcube webmail to version 0.8.7 or 0.9.5 or later.
What types of attacks can exploit CVE-2013-6172?
CVE-2013-6172 can be exploited to conduct SQL injection attacks, read arbitrary files, and execute arbitrary code.
Which versions of Roundcube are affected by CVE-2013-6172?
CVE-2013-6172 affects all versions of Roundcube webmail prior to 0.8.7 and 0.9.x versions before 0.9.5.
Is there any workaround for CVE-2013-6172?
There are no official workarounds for CVE-2013-6172, and upgrading to the latest version is the recommended solution.