github.com
https://github.com/roundcube/roundcubemail/releases CVE-2024-42008
CRITICAL
Record summary
CVE-2024-42008 has a selected CVSS score of 9.3 (critical); EIP currently links 3 repository PoCs.
Description
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 3
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 7, 2024 · Source: CVE List
Proofs of concept
3Repository PoCs
GitHubrpgsec/Roundcube-CVE-2024-42008-POCRepository PoCby rpgsecStars: 0Not analyzed2 files
GitHubvictoni/Roundcube-CVE-2024-42008-and-CVE-2024-42010-POCRepository PoCby victoniStars: 2Not analyzed4 files
GitHubFoxer131/CVE-2024-42008-9-exploitRepository PoCby Foxer131Stars: 0Not analyzed3 files
References
6github.com
https://github.com/roundcube/roundcubemail/releases/tag/1.5.8 github.com
https://github.com/roundcube/roundcubemail/releases/tag/1.6.8 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-42008 roundcube.net
https://roundcube.net/news/2024/08/04/security-updates-1.6.8-and-1.5.8 sonarsource.com
https://sonarsource.com/blog/government-emails-at-risk-critical-cross-site-scripting-vulnerability-in-roundcube-webmail