CVE-2021-44025: XSS
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-44025?
CVE-2021-44025 is a vulnerability in Roundcube Webmail before version 1.3.17 and 1.4.x before version 1.4.12 that allows for cross-site scripting (XSS) attacks.
What is the severity of CVE-2021-44025?
CVE-2021-44025 has a severity score of 6.1, making it a medium-level vulnerability.
How does CVE-2021-44025 work?
CVE-2021-44025 occurs when Roundcube Webmail fails to properly handle an attachment's filename extension, leading to potential XSS attacks when displaying a MIME type warning message.
Which software versions are affected by CVE-2021-44025?
CVE-2021-44025 affects Roundcube Webmail versions prior to 1.3.17 and versions 1.4.0 to 1.4.12.
How can I mitigate CVE-2021-44025?
To mitigate CVE-2021-44025, it is recommended to update Roundcube Webmail to version 1.3.17 or higher for versions prior to 1.4.0, and to version 1.4.12 or higher for versions 1.4.0 to 1.4.12.