Bug 2343585 (CVE-2024-57004) - CVE-2024-57004 roundcubemail: XSS via malicious email attachment
Summary: CVE-2024-57004 roundcubemail: XSS via malicious email attachment
Keywords:
Status: NEW
Alias: CVE-2024-57004
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2343660 2343659
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-02-03 19:01 UTC by OSIDB Bzimport
Modified: 2025-02-03 23:14 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-02-03 19:01:09 UTC
Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.


Note You need to log in before you can comment on or make changes to this bug.