Where
-Infinity
0

Hanno Böck je 2. 6. 25 ob 07:26 napisal: Roundcube just published an update that appears to contain an important security fix: https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10

"Fix Post-Auth RCE via PHP Object Deserialization reported by firs0v."

Even though it says "Post-Auth", impact is likely high, as for a webmailer, it is a very common scenario that many people are potentially authenticated. (And it may just be another XSS away from non-authenticated RCE.) I believe this is

https://www.cve.org/CVERecord?id=CVE-2025-49113

CVE-2025-49113 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H score 9.9

Severity
7.2
SQL Injection
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg WordPress plugin before 2.7.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins

First published (updated )
Severity
6.1
XSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.

First published (updated )
Severity
7.5
Path Traversal
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Remedy

Upgrade to version 2.01
First published (updated )
Severity
7.5
Input Validation
AV:N/AC:L/Au:N/C:P/I:P/A:P

BarnOwl before 1.6.2 does not check the return code of calls to the (1) ZPending and (2) ZReceiveNotice functions in libzephyr, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.

First published (updated )

Not associated with Roundcube but didn't see posts about this yet.

On August 4, the Roundcube project released versions 1.6.8 and 1.5.8 (LTS) of their webmail client with fixes for several XSS vulnerabilities in HTML e-mail display. From the announcement page at <https://roundcube.net/news/2024/08/04/security-updates-1.6.8-and-1.5.8>:

Fix XSS vulnerability in post-processing of sanitized HTML content [CVE-2024-42009] Fix XSS vulnerability in serving of attachments other than HTML or SVG [CVE-2024-42008] Fix information leak (access to remote content) via insufficient CSS filtering [CVE-2024-42010]

Links to both releases are on the abovementioned page.

-Valtteri

Severity
7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P

Multiple PHP remote file inclusion vulnerabilities in barnraiser AROUNDMe 0.7.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) languagepathcore parameter to inc/coreprofile.header.php, the (2) templatepathcore parameter to template/barnraiser01/maintcontactview.tpl.php, and the (3) templatepath parameter to template/barnraiser01/default.tpl.php. NOTE: this issue might overlap CVE-2006-5533.

First published (updated )
Severity
6.8
Code Injection
AV:N/AC:M/Au:N/C:P/I:P/A:P

PHP remote file inclusion vulnerability in components/core/connect.php in AROUNDMe 1.1 and earlier, when registerglobals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the languagepath parameter.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:N/A:P

include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an arbitrary URL, and cause a denial of service (resource consumption and inbox outage), via a Subject header containing only a URL, a related issue to CVE-2011-3379.

First published (updated )
Severity
8.8
Code Injection
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulkactionlistener remote code execution.

First published (updated )
EOL
Jul 28, 2022

End of life: 7/28/2022, Latest version: 1.3.17

First published (updated )
EOL
Jul 28, 2022

End of life: 7/28/2022, Latest version: 1.3.17

First published (updated )
EOL
Oct 18, 2021

End of life: 10/18/2021, Latest version: 1.2.13

First published (updated )
EOL
Oct 18, 2021

End of life: 10/18/2021, Latest version: 1.2.13

First published (updated )

Latest version: 1.1.12

First published (updated )

Latest version: 1.1.12

First published (updated )

Latest version: 1.0.12

First published (updated )

Latest version: 1.0.12

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203