Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-42010. PoCs published by victoni.
AI-analyzed exploit summary This repository contains a functional proof-of-concept for exploiting CVE-2024-42008 (XSS via malicious XML attachment) and CVE-2024-42010 (HTML exfiltration via CSS injection) in Roundcube Webmail. The PoC includes a JavaScript server to exfiltrate the UID of the malicious attachment.
Description
mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information.
Exploits (1)
This repository contains a functional proof-of-concept for exploiting CVE-2024-42008 (XSS via malicious XML attachment) and CVE-2024-42010 (HTML exfiltration via CSS injection) in Roundcube Webmail. The PoC includes a JavaScript server to exfiltrate the UID of the malicious attachment.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N