Showing 2 vulnerabilities on this page for roundcube_webmail

Signals CISA KEV Ransomware Nuclei
Roundcube vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.

CWE-77Jun 7, 2024
CVSS9.8v3.1EPSS1.48%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.

CWE-79Jun 7, 2024
CVSS6.1v3.1EPSS0.498%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX