CVE-2021-44026
CRITICAL KEVRoundcube Webmail < 1.3.17 - SQL Injection
Title source: ruleDescription
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
Exploits (2)
nomisec
WORKING POC
13 stars
by pentesttoolscom · remote
https://github.com/pentesttoolscom/roundcube-cve-2021-44026
References (8)
Scores
CVSS v3
9.8
EPSS
0.7253
EPSS Percentile
98.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2023-06-22
VulnCheck KEV
2023-06-20
InTheWild.io
2023-06-22
ENISA EUVD
EUVD-2021-30885
CWE
CWE-89
Status
published
Products (6)
debian/debian_linux
9.0
debian/debian_linux
10.0
debian/debian_linux
11.0
fedoraproject/fedora
33
fedoraproject/fedora
34
roundcube/webmail
< 1.3.17
Published
Nov 19, 2021
KEV Added
Jun 22, 2023
Tracked Since
Feb 18, 2026