Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2840-1 | roundcube security update |
Debian DSA |
DSA-5013-1 | roundcube security update |
EUVD |
EUVD-2021-30884 | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message. |
Ubuntu USN |
USN-5182-1 | Roundcube Webmail vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T04:10:17.205Z
Reserved: 2021-11-19T00:00:00
Link: CVE-2021-44025
No data.
Status : Modified
Published: 2021-11-19T04:15:06.900
Modified: 2024-11-21T06:30:14.413
Link: CVE-2021-44025
No data.
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN