Roundcube has released versions 1.6.18 and 1.7.3 to address eleven security vulnerabilities affecting its webmail platform. The updates fix a remote code execution flaw, server-side request forgery bypasses, injection vulnerabilities, and stored cross-site scripting issues. Administrators using Roundcube 1.6.x or 1.7.x should update as soon as possible. The most serious issue is a remote code execution vulnerability in the markasjunk plugin. The flaw affects the plugin’s cmd_learn driver, which is used to send messages to a spam-learning backend. Security researcher nept1337 reported the issue. Successful exploitation could allow an attacker to execute commands within the affected Roundcube environment, posing a direct risk to the...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!