CVE-2021-44026

CRITICAL KEV

Roundcube Webmail < 1.3.17 - SQL Injection

Title source: rule

Description

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

Exploits (2)

nomisec WORKING POC 13 stars
by pentesttoolscom · remote
https://github.com/pentesttoolscom/roundcube-cve-2021-44026
nomisec WORKING POC
by skyllpro · client-side
https://github.com/skyllpro/CVE-2021-44026-PoC

Scores

CVSS v3 9.8
EPSS 0.7253
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2023-06-22
VulnCheck KEV 2023-06-20
InTheWild.io 2023-06-22
ENISA EUVD EUVD-2021-30885
CWE
CWE-89
Status published
Products (6)
debian/debian_linux 9.0
debian/debian_linux 10.0
debian/debian_linux 11.0
fedoraproject/fedora 33
fedoraproject/fedora 34
roundcube/webmail < 1.3.17
Published Nov 19, 2021
KEV Added Jun 22, 2023
Tracked Since Feb 18, 2026