CVE-2017-8114

HIGH

Roundcube Webmail < 1.0.11, 1.1.x < 1.1.9, 1.2.x < 1.2.5 - Authenticated Arbitrary Password Reset via Password Plugin

Title source: llm
STIX 2.1

Description

Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.

References (4)

Core 4
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201707-11
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/98445

Scores

CVSS v3 8.8
EPSS 0.0347
EPSS Percentile 87.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (1)
roundcube/webmail < 1.0.11
Published Apr 29, 2017
Tracked Since Feb 18, 2026