VDB

GCVE-110-MAGEIA-2020-206

GCVE-110-MAGEIA-2020-206
Advisory Published
Vulnetix · Advisory published May 8, 2020
Updated roundcubemail packages fix security vulnerabilities: - Cross-Site Scripting (XSS) via malicious HTML content (CVE-2020-12625) - CSRF attack can cause an authenticated user to be logged out (CEV-2020-12626) - Remote code execution via crafted config options - Path traversal vulnerability allowing local file inclusion via crafted 'plugins' option

Affected Products

VendorProductVersionsPlatforms
Mageiallvm0 (affected), 8.0.0-1.1.mga7 (unaffected)
Mageiaroundcubemail0 (affected), 1.3.11-1.mga7 (unaffected), 0 (affected), 1.3.11-1.mga7 (unaffected)
Mageiarust0 (affected), 1.43.1-1.mga7 (unaffected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›