CVE-2024-42009: RoundCube Webmail Cross-Site Scripting Vulnerability
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in messagebody() in program/actions/mail/show.php.
Other sources
RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in messagebody() in program/actions/mail/show.php.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42009?
CVE-2024-42009 is considered a critical severity vulnerability due to its potential impact on user data privacy.
How do I fix CVE-2024-42009?
To fix CVE-2024-42009, upgrade to Roundcube version 1.5.8 or 1.6.8 and later.
What is the nature of the vulnerability CVE-2024-42009?
CVE-2024-42009 is a Cross-Site Scripting vulnerability that allows remote attackers to exploit Desanitization issues.
Which versions of Roundcube are affected by CVE-2024-42009?
CVE-2024-42009 affects Roundcube versions prior to 1.5.8 and 1.6.0 through 1.6.7.
Can CVE-2024-42009 allow sensitive data theft?
Yes, CVE-2024-42009 can enable attackers to steal sensitive information by executing scripts in a victim's browser.