Cross-site scripting in Roundcube Webmail - CVE-2024-37384
Published: May 21, 2024 / Updated: June 26, 2024
Vulnerability details
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data when handling list columns from user preferences. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Debian Linux
Fedora
Ubuntu
roundcube (Ubuntu package)
roundcube-core (Ubuntu package)
roundcube (Debian package)
roundcubemail
How to mitigate CVE-2024-37384
roundcube (Ubuntu package) - addressed in versions Ubuntu Pro, 1.6.2+dfsg-1ubuntu0.2
roundcube-core (Ubuntu package) - addressed in versions Ubuntu Pro, 1.6.2+dfsg-1ubuntu0.2
roundcube (Debian package) - addressed in versions 1.4.15+dfsg.1-1+deb11u3, 1.6.5+dfsg-1+deb12u2
roundcubemail - addressed in versions 1.5.7-1.el9, 1.6.7-1.fc39, 1.6.7-1.fc40