ZeroHour

CVE-2021-44026

KEVmass1

SQL Injection in Roundcube Webmail via Search Parameters

CISA: Roundcube Webmail SQL Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
42%p99
Published
()
KEV added
AI analysis

Roundcube Webmail contains a SQL injection flaw (CWE-89) in which attacker-controlled 'search' or 'search_params' input is incorporated into database queries without sufficient sanitization. An attacker with access to the webmail search functionality (typically an authenticated mailbox user) can submit crafted parameters to execute arbitrary SQL against the Roundcube backend database, potentially reading or modifying stored mail account data. Any organization running Roundcube is affected, including self-hosted mail servers and customers of hosting providers that ship Roundcube as their bundled webmail client. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-06-22, indicating exploitation in the wild, and EPSS assigns a 41.9% probability of exploitation within 30 days (99th percentile). No public proof-of-concept is known, and CISA lists ransomware use as unknown.

What to do: Apply vendor updates per Roundcube's instructions by upgrading to the latest patched, supported release, prioritizing internet-facing webmail servers; federal agencies must remediate per the CISA KEV requirement. If Roundcube is managed by a hosting provider (e.g., via cPanel), coordinate patching with them. In the interim, restrict webmail exposure and review database and web logs for anomalous search-related queries that may indicate exploitation.

Affected
Roundcube Webmail
Estimated exposure
massmillions of users across tens of thousands of exposed Roundcube deployments (estimated) — Roundcube is the default webmail client bundled with cPanel/WHM and many hosting control panels and is self-hosted by ISPs, universities, and enterprises, so public internet-wide scans have long shown on the order of tens of thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

CISA Known Exploited Vulnerability
Affected
Roundcube Roundcube Webmail
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
roundcubefedoraprojectdebian
Products
webmail, fedora, debian linux
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news