CVE-2024-42008: and moXSS vulnerabilities in Roundcube webmail
Published Aug 5, 2024
·Updated
A Cross-Site Scripting vulnerability in rcmailactionmailget->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.
Affected Software
2 affected components
Roundcube Webmail<1.5.8
Roundcube Webmail>=1.6.0<1.6.8
Event History
Aug 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42008?
CVE-2024-42008 is classified as a critical severity Cross-Site Scripting vulnerability.
2
How do I fix CVE-2024-42008?
To fix CVE-2024-42008, upgrade Roundcube to version 1.5.8 or 1.6.8 and above.
3
Which versions of Roundcube are affected by CVE-2024-42008?
Versions of Roundcube from 1.5.7 and 1.6.0 to 1.6.7 are affected by CVE-2024-42008.
4
What type of attack is associated with CVE-2024-42008?
CVE-2024-42008 is associated with a Cross-Site Scripting attack that can allow attackers to steal emails.
5
Can CVE-2024-42008 lead to data theft?
Yes, CVE-2024-42008 can lead to unauthorized access and theft of emails due to its exploitation capabilities.