VDB
BDU%3A2024-06146
BDU%3A2024-06146
PUBLISHED
CVSS 9.399999618530273 CRITICAL
Уязвимость функции message_body() файла program/actions/mail/show.php почтового клиента RoundCube Webmail, позволяющая нарушителю получить полный доступ к электронной почте путём отправки специально сформированного сообщения
Risk Scores
CVSS 2.0
9.399999618530273
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| ООО «Ред Софт», The RoundCube Team | РЕД ОС (запись в едином реестре российских программ №3751), RoundCube Webmail |
Timeline
- Aug 5, 2024 CVE Published
- Aug 5, 2024 PoC Published
- Aug 7, 2024 PoC Published
- Jan 20, 2025 PoC Published
- Feb 12, 2025 PoC Published
- Feb 13, 2025 PoC Published
- Feb 13, 2025 PoC Published
- Feb 14, 2025 PoC Published
- Jun 6, 2025 PoC Published
- Jun 6, 2025 PoC Published
- Jun 7, 2025 PoC Published
- Jun 9, 2025 PoC Published
References
- https://github.com/roundcube/roundcubemail/releases/tag/1.5.8 url
- https://github.com/roundcube/roundcubemail/releases advisory
- https://sonarsource.com/blog/government-emails-at-risk-critical-cross-site-scripting-vulnerability-in-roundcube-webmail/ url
- https://roundcube.net/news/2024/08/04/security-updates-1.6.8-and-1.5.8 url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-42009 url
- https://www.cisa.gov/sites/default/files/csv/known_exploited_vulnerabilities.csv url
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.8 advisory
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory