Record summary

CVE-2024-42010 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC.

Description

mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE ListThrough 1.5.7affected
1.6x to ≤ 1.6.7affected

Proofs of concept

1

Repository PoCs

GitHubvictoni/Roundcube-CVE-2024-42008-and-CVE-2024-42010-POCRepository PoCby victoniStars: 2Not analyzed4 files

311.4 KiB · linked to 2 vulnerabilities

GitHub

PoC details

References

6