Roundcube 1.6.18 and 1.7.3 Released With Fix for RCE and SSRF Vulnerabilities
Brief
Roundcube has released versions 1.
- 18 and 1.
- 3 to address eleven security vulnerabilities affecting its webmail platform. The updates fix a remote code execution flaw, server-side request forgery bypasses, injection vulnerabilities, and stored cross-site scripting issues.
Administrators using Roundcube 1.
- x or 1.
- x should update as soon as possible. The most serious issue is a remote code execution vulnerability in the markasjunk plugin. The flaw affects the plugin’s cmd_learn driver, which is used to send messages to a spam-learning backend.
Security researcher nept1337 reported the issue. Successful exploitation could allow an attacker to execute commands within the affected Roundcube environment, posing a direct risk to the webmail server and potentially to other systems reachable from it.
Roundcube is widely used as a browser-based interface for email services.
