ZeroHour
Security Affairspublished ()ingested @securityaffairs

Critical XSS bug in Roundcube Webmail allows attackers to steal emails and sensitive data

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-42009
+1 in the same advisory: …42008
Cross-Site Scripting in Roundcube Webmail Lets Attackers Steal Emails

CVE-2024-42009 is a cross-site scripting (CWE-79) vulnerability in Roundcube Webmail versions through 1.5.7 and 1.6.x through 1.6.7, caused by a desanitization issue in message_body() in program/actions/mail/show.php. An attacker sends a specially crafted email, and when the victim opens it in the Roundcube interface, injected script runs in the context of the victim's webmail session (no privileges are required, but user interaction is needed, per the CVSS UI:R vector). Successful exploitation lets the attacker steal the victim's emails and send messages as the victim, and related reporting notes that, chained with the companion flaw CVE-2024-42008, attackers can compromise email accounts and passwords. Any organization or provider self-hosting an affected Roundcube version is exposed, including universities, hosting providers, enterprises, and government mail systems. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-06-09, EPSS is 82.9% (100th percentile), and recent headlines describe suspected China-aligned espionage activity using Roundcube exploit chains against universities.

Do: Upgrade Roundcube to a point release newer than 1.6.7 on the 1.6.x line or newer than 1.5.7 on the 1.5.x line (the latest vendor release of each branch), per vendor instructions; organizations under BOD 22-01 must apply the required mitigations by the KEV due date or discontinue use. Also patch the companion issue CVE-2024-42008 to prevent chained account compromise. Review webmail access logs for suspicious requests to the mail show handler, check sent-mail folders for messages sent unexpectedly as users, and rotate sessions/credentials for potentially targeted accounts.

9.383% KEV
  • Roundcube Webmail all versions through 1.5.7 and all 1.6.x versions through 1.6.7
massroughly millions of users across tens of thousands of self-hosted instances (public scans show tens of thousands of internet-exposed Roundcube servers)
CVE-2024-42010
mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail message

mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information.

NVD description · AI analysis pending
7.553%
Full article353 words · extracted from securityaffairs.com · click to collapse

Researchers warn of flaws in the Roundcube webmail software that could be exploited to steal sensitive information from target accounts.

Sonar’s Vulnerability Research Team discovered a critical Cross-Site Scripting (XSS) vulnerability in the popular open-source webmail software Roundcube. Roundcube is included by default in the server hosting panel cPanel which has millions of installations worldwide.

An attacker can trigger the vulnerability to execute arbitrary JavaScript in the victim’s browser when they view a malicious email, potentially leading to the theft of emails, contacts, passwords, and unauthorized email sending.

Experts pointed out that government employees’ emails are a valuable target for APT groups carrying out cyber espionage campaigns. In October 2023, ESET Research revealed that a similar vulnerability was exploited by the APT group Winter Vivern to target European government entities.

The experts discovered two XSS vulnerabilities tracked as CVE-2024-42009 and CVE-2024-42008, which have critical and high ratings respectively. The flaws impact Roundcube version 1.6.7 and below, and version 1.5.7 and below.

No user interaction is required to successfully exploit the CVE-2024-42009, while for CVE-2024-42008, a single click by the victim is needed.

“These allow an unauthenticated attacker to steal emails and contacts, as well as send emails from a victim’s account. All the victim user has to do is view a malicious email in Roundcube.” reads the report published by Sonar. “Attackers can gain a persistent foothold in the victim’s browser across restarts, allowing them to exfiltrate emails continuously or steal the victim’s password the next time it is entered.”

The company did not disclose technical details of the vulnerabilities to give administrators time to update. However, APT groups may still discover the way to weaponize these flaws. Researchers strongly recommend Roundcube administrators apply the latest patches (version 1.6.8 or 1.5.8) immediately. Affected users should change their email passwords and clear their browser’s site data for Roundcube.

The experts also discovered an information disclosure vulnerability, tracked as CVE-2024-42010, that is caused by insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, roundcube)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/166736/hacking/critical-xss-bug-in-roundcube-webmail.html