Vulnerabilities
Vulnerable Software
Roundcube:  >> Webmail  >> 1.6.6  Security Vulnerabilities
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.
CVSS Score
6.1
EPSS Score
0.005
Published
2024-06-07
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.
CVSS Score
9.8
EPSS Score
0.015
Published
2024-06-07


Contact Us

Shodan ® - All rights reserved