CVE-2015-8770: Path Traversal
Directory traversal vulnerability in the setskin function in program/include/rcmailoutputhtml.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the skin parameter to index.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8770?
CVE-2015-8770 is classified as a high-severity vulnerability due to its potential to allow unauthorized access to sensitive files.
How do I fix CVE-2015-8770?
To remediate CVE-2015-8770, upgrade Roundcube Webmail to version 1.0.8 or 1.1.4 and later.
Who is affected by CVE-2015-8770?
CVE-2015-8770 affects Roundcube Webmail versions prior to 1.0.8 and all 1.1.x versions prior to 1.1.4.
What type of attack does CVE-2015-8770 allow?
CVE-2015-8770 can enable directory traversal attacks, allowing authenticated users to read arbitrary files on the server.
What is the impact of CVE-2015-8770 on the system?
The impact of CVE-2015-8770 includes potential exposure of sensitive information and possible execution of arbitrary code.