Описание
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| roundcube | fixed | 1.6.14+dfsg-1 | package |
Примечания
https://roundcube.net/news/2026/03/18/security-updates-1.7-rc5-1.6.14-1.5.14
Fixed by: https://github.com/roundcube/roundcubemail/commit/5fe8a69956a9683a4269f3ad2a68e18deebf8a15 (1.7-rc5)
Fixed by: https://github.com/roundcube/roundcubemail/commit/b18a8fa8e81571914c0ff55d4e20edb459c6952c (1.6.14)
Regression fix: https://github.com/roundcube/roundcubemail/commit/6b137adda9b042c3742b0f968692e95ed367d3d1 (1.6.15)
Fixed by: https://github.com/roundcube/roundcubemail/commit/7daf5aa9c190ccc75bb31672d8fee9938877fd64 (1.5.14)
Regression fix: https://github.com/roundcube/roundcubemail/commit/c360f32adc8754aea91dcc347edcf394108ca110 (1.5.15)
EPSS
Связанные уязвимости
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.
Roundcube Webmail: Unsanitized IMAP SEARCH command arguments
Уязвимость почтового клиента RoundCube Webmail, связанная с внедрением или модификацией аргументов, позволяющая нарушителю осуществить CSRF-атаку
EPSS