The U.S. Cybersecurity and Infrastructure Security Agency (CISA) a Roundcube Webmail Persistent Cross-Site Scripting (XSS) vulnerability, tracked as , to its .
Roundcube is an open-source web-based email client. It provides a user-friendly interface for accessing email accounts via a web browser. Users can send and receive emails, manage their contacts, organize messages into folders, and perform various other email-related tasks. Roundcube supports standard email protocols such as IMAP and SMTP, making it compatible with a wide range of email servers.
The exploitation of the vulnerability can lead to information disclosure via malicious link references in plain/text messages.
The vulnerability was discovered by Niraj Shivtarka, it impacts Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3. The vulnerability was fixed with the release of version 1.6.3.
According to , FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts recommend also private organizations review the and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this vulnerability by March 4, 2024.
In October, Russia-linked APT group Winter Vivern (aka TA473) was observed exploiting another zero-day flaw in Roundcube webmail software.
ESET researchers pointed out that is a different vulnerability than , that the group exploited in other attacks.
ESET reported the zero-day to Roundcube, and the company patched the issue on October 14th, 2023. The vulnerability affects Roundcube versions 1.6.x before 1.6.4, 1.5.x before 1.5.5, and 1.4.x before 1.4.15.
Follow me on Twitter: and and Mastodon
(SecurityAffairs – Hacking, Known Exploited Vulnerabilities catalog)