First published: Mon Feb 03 2025(Updated: )
Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Roundcube Webmail |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-57004 is classified as a high severity vulnerability due to its potential for exploitation by authenticated users.
To mitigate CVE-2024-57004, users should upgrade to the latest version of Roundcube Webmail.
CVE-2024-57004 affects users of Roundcube Webmail version 1.6.9 and prior versions.
CVE-2024-57004 is a Cross-Site Scripting (XSS) vulnerability.
An attacker can upload a malicious file that leads to XSS by visiting the SENT session in Roundcube Webmail.