ZeroHour

CVE-2018-1000071

PoC
CVSS 3.0
7.5 high
EPSS
2%p76
Published
()
Modified
Description

roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity.

Vendors
roundcube
Products
webmail
Weakness
CWE-732
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.