Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-46pv-mj2g-93gh

Опубликовано: 03 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.2

Описание

Roundcube Webmail: Incorrect password comparison in the password plugin

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.

Пакеты

Наименование

roundcube/roundcubemail

composer
Затронутые версииВерсия исправления

>= 1.7-beta, < 1.7-rc5

1.7-rc5

EPSS

Процентиль: 16%
0.00243
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-843

Связанные уязвимости

CVSS3: 4.2
ubuntu
4 месяца назад

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.

CVSS3: 4.2
nvd
4 месяца назад

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.

CVSS3: 4.2
debian
4 месяца назад

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. ...

CVSS3: 4.2
fstec
5 месяцев назад

Уязвимость сценария password.php плагина password почтового клиента RoundCube Webmail, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

CVSS3: 4.2
redos
3 месяца назад

Уязвимость roundcubemail

EPSS

Процентиль: 16%
0.00243
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-843