Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q4q9-gcgm-p77w

Опубликовано: 14 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

EPSS

Процентиль: 18%
0.00259
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 6.4
ubuntu
23 дня назад

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

CVSS3: 6.4
nvd
23 дня назад

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

CVSS3: 6.4
debian
23 дня назад

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the passwor ...

EPSS

Процентиль: 18%
0.00259
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-290