ZeroHour

CVE-2024-57004

PoC mass

Stored XSS in Roundcube Webmail 1.6.9 via Malicious Email Attachment

CVSS 3.1
6.1 medium
EPSS
29%p98
Published
()
Modified
AI analysis

Roundcube Webmail 1.6.9 contains a cross-site scripting flaw (CWE-80) in its attachment handling. An authenticated user can upload a malicious file as an email attachment, and the injected script executes when the SENT session is subsequently visited — for example, when the victim or another user views sent messages. Successful exploitation lets the attacker run arbitrary JavaScript in the victim's browser context, potentially hijacking the webmail session, stealing credentials or cookies, or reading mailbox content. Any organization or hosting provider serving Roundcube 1.6.9 webmail is exposed, which includes large numbers of end users at ISPs, universities, and cPanel-based hosting environments. A public proof-of-concept exists but the issue is not yet listed in CISA KEV; the high EPSS score (28.8%, 98th percentile) indicates an elevated likelihood of exploitation in the next 30 days.

What to do: Upgrade Roundcube to the latest patched 1.6.x release, checking the vendor's security advisory for the fixed version, since exploitation requires only an authenticated upload and a victim viewing sent mail. As interim mitigation, restrict or sanitize attachment types and consider disabling or limiting access to the sent-message preview. Review webmail logs for suspicious attachment uploads and anomalous access to SENT sessions, and prioritize patching given the elevated EPSS score.

Affected
Roundcube Webmail1.6.9 (as reported in the advisory; no broader version range specified)
Estimated exposure
massmillions of end users via tens of thousands of deployed instances — Roundcube is the default webmail client bundled with cPanel/WHM and many hosting and mail-server stacks, giving it a very large global user base, while public internet scans typically show tens of thousands of exposed Roundcube instances.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.

Vendors
roundcube
Products
webmail
Weakness
CWE-80
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.