CVE-2021-44026: Roundcube Webmail SQL Injection Vulnerability
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or searchparams.
Other sources
Roundcube Webmail is vulnerable to SQL injection via search or searchparams.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.3.17+dfsg.1-1~deb10u2Fixed in 1.3.17+dfsg.1-1~deb10u3Fixed in 1.4.14+dfsg.1-1~deb11u1Fixed in 1.4.13+dfsg.1-1~deb11u1Fixed in 1.6.3+dfsg-1~deb12u1Fixed in 1.6.4+dfsg-1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2021-44026?
CVE-2021-44026 is a vulnerability known as Roundcube Webmail SQL Injection Vulnerability.
How does the Roundcube Webmail SQL Injection vulnerability work?
The Roundcube Webmail SQL Injection vulnerability allows an attacker to inject SQL commands via search or search_params and potentially gain unauthorized access to the database.
What software is affected by CVE-2021-44026?
Roundcube Webmail versions 1.4.11 and earlier, and versions 1.3.16 and earlier, are affected by this vulnerability.
How can I fix the Roundcube Webmail SQL Injection vulnerability?
To fix the Roundcube Webmail SQL Injection vulnerability, update to version 1.4.12 or 1.3.17, which contain the necessary security patches.
What is the severity of CVE-2021-44026?
The severity of CVE-2021-44026 is high.