Impact
An LDAP search filter in Roundcube Webmail allows attackers to inject special format specifiers (%u/%fu/%d) without proper escaping. This injection can manipulate the LDAP query sent to the directory server, potentially exposing sensitive directory information or allowing privilege escalation. The flaw originates from unsanitized user input processing.
Affected Systems
Roundcube Webmail versions earlier than 1.6.18 and 1.7.x earlier than 1.7.3 are affected. All releases prior to those versions are vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV, suggesting limited exploitation evidence so far. Because the flaw involves LDAP query manipulation, an attacker who can submit crafted webmail requests may exploit the format specifiers to extract directory entries or elevate privileges, especially if the LDAP service grants elevated rights. The most likely attack vector is through webmail input that triggers the LDAP search.
OpenCVE Enrichment