CVE-2020-12626 PUBLISHED

An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.

EPSS 1.29% · 79.5th percentile

Risk Scores

EPSS Score
1.29%
79.5th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:20.04:LTSroundcube1.4.3+dfsg.1-1, 1.4.2+dfsg.1-2, 1.4.2+dfsg.1-1
Ubuntu:Pro:16.04:LTSroundcube0, 1.1.1+dfsg.1-2, 1.1.2+dfsg.1-5
Ubuntu:Pro:18.04:LTSroundcube*, 0, 1.3.6+dfsg.1-1ubuntu0.1~esm1

Timeline

References

Open in Interactive Console →