Back to search
CVE-2021-44025
Published: Nov 19, 2021
Modified: Aug 4, 2024
PUBLISHED
Description
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugs.debian.org/1000156
x_refsource_MISC
https://github.com/roundcube/roundcubemail/issues/8193
x_refsource_MISC
FEDORA-2021-167865df98
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-43d3c10590
vendor-advisory
x_refsource_FEDORA
DSA-5013
vendor-advisory
x_refsource_DEBIAN
[debian-lts-announce] 20211206 [SECURITY] [DLA 2840-1] roundcube security update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now