CVE-2024-57004
PoC massStored XSS in Roundcube Webmail 1.6.9 via Malicious Email Attachment
Roundcube Webmail 1.6.9 contains a cross-site scripting flaw (CWE-80) in its attachment handling. An authenticated user can upload a malicious file as an email attachment, and the injected script executes when the SENT session is subsequently visited — for example, when the victim or another user views sent messages. Successful exploitation lets the attacker run arbitrary JavaScript in the victim's browser context, potentially hijacking the webmail session, stealing credentials or cookies, or reading mailbox content. Any organization or hosting provider serving Roundcube 1.6.9 webmail is exposed, which includes large numbers of end users at ISPs, universities, and cPanel-based hosting environments. A public proof-of-concept exists but the issue is not yet listed in CISA KEV; the high EPSS score (28.8%, 98th percentile) indicates an elevated likelihood of exploitation in the next 30 days.
What to do: Upgrade Roundcube to the latest patched 1.6.x release, checking the vendor's security advisory for the fixed version, since exploitation requires only an authenticated upload and a victim viewing sent mail. As interim mitigation, restrict or sanitize attachment types and consider disabling or limiting access to the sent-message preview. Review webmail logs for suspicious attachment uploads and anomalous access to SENT sessions, and prioritize patching given the elevated EPSS score.
| Roundcube Webmail | 1.6.9 (as reported in the advisory; no broader version range specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.
- Vendors
- roundcube
- Products
- webmail
- Weakness
- CWE-80
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.