CVE-2020-12626: CSRF
An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-12626?
CVE-2020-12626 is a vulnerability found in Roundcube Webmail before version 1.4.4 that allows a CSRF attack to log out an authenticated user.
How severe is CVE-2020-12626?
CVE-2020-12626 has a severity rating of 6.5, which is considered high.
How does CVE-2020-12626 affect Roundcube Webmail?
CVE-2020-12626 affects Roundcube Webmail versions prior to 1.4.4.
What is the remedy for CVE-2020-12626 in Debian?
The remedy for CVE-2020-12626 in Debian is to update Roundcube to version 1.4.4 or higher.
Where can I find more information about CVE-2020-12626?
You can find more information about CVE-2020-12626 at the following references: [GitHub Commit](https://github.com/roundcube/roundcubemail/commit/9bbda422ff0b782b81de59c86994f1a5fd93f8e6), [GitHub Comparison](https://github.com/roundcube/roundcubemail/compare/1.4.3...1.4.4), [GitHub Pull Request](https://github.com/roundcube/roundcubemail/pull/7302).