Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-11-09T14:00:00
Updated: 2024-08-05T20:27:04.304Z
Reserved: 2017-11-07T00:00:00
Link: CVE-2017-16651
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-11-09T14:29:00.267
Modified: 2024-11-21T03:16:45.910
Link: CVE-2017-16651
Redhat
No data.