
Cloud Vulnerability DB
A community-led vulnerabilities database
A Cross-Site Scripting (XSS) vulnerability was discovered in Roundcube Mail versions 1.4.4 and earlier, specifically in the SMTP configuration section of the installer at /installer/test.php. The vulnerability was reported on May 29, 2020, and was subsequently patched in version 1.4.5 released on June 2, 2020 (Roundcube News, GitHub Issue).
The vulnerability is classified with a CVSS v3.1 Base Score of 5.4 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N. The issue stems from insufficient input validation in the SMTP configuration section of the installer, specifically in the /installer/test.php file. The vulnerability is related to the handling of SMTP configuration parameters that are not properly sanitized before being displayed in the installer interface (NVD).
The vulnerability allows an attacker to execute cross-site scripting attacks through the SMTP configuration parameters in the installer. While the impact is somewhat limited due to the vulnerability being in the installer component, it could potentially lead to session hijacking or other client-side attacks if an administrator accesses the installer while the malicious payload is present (NVD).
The vulnerability requires an attacker to have access to the installer interface and the ability to modify SMTP configuration parameters. The attack requires user interaction, as an administrator would need to access the affected installer page for the XSS payload to execute (NVD).
The vulnerability was fixed in Roundcube Mail version 1.4.5. Users are strongly recommended to upgrade to this version or later. For those unable to upgrade immediately, limiting access to the installer directory and completing the installation process can help mitigate the risk (Roundcube News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."