https://seclists.org/oss-sec/2024/q3/190: CVE-2024-42008 and moXSS vulnerabilities in Roundcube webmail
Published Aug 12, 2024
·Updated
Affected Software
1 affected component
Roundcube Roundcube
Frequently Asked Questions
1
What is the severity of CVE-2024-42008?
CVE-2024-42008 has been classified as a high severity vulnerability due to its potential for exploitation through cross-site scripting.
2
How do I fix CVE-2024-42008?
To fix CVE-2024-42008, update your Roundcube installation to versions 1.6.8 or 1.5.8 (LTS) or later.
3
What are the main vulnerabilities addressed in CVE-2024-42008?
CVE-2024-42008 addresses several XSS vulnerabilities in the HTML email display functionality of Roundcube webmail.
4
Is Roundcube affected by CVE-2024-42008?
Yes, Roundcube versions prior to 1.6.8 and 1.5.8 (LTS) are vulnerable to the issues described in CVE-2024-42008.
5
When was CVE-2024-42008 published?
CVE-2024-42008 was published on August 12, 2024.