Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qhxr-pc4x-jrq3

Опубликовано: 26 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)

EPSS

Процентиль: 34%
0.00414
Низкий

7.5 High

CVSS3

Дефекты

CWE-670

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)

CVSS3: 7.5
nvd
2 месяца назад

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)

CVSS3: 7.5
debian
2 месяца назад

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insec ...

CVSS3: 7.5
fstec
3 месяца назад

Уязвимость реализации протокола LDAP почтового клиента RoundCube Webmail, позволяющая нарушителю выполнить произвольный код

suse-cvrf
2 месяца назад

Security update for roundcubemail

EPSS

Процентиль: 34%
0.00414
Низкий

7.5 High

CVSS3

Дефекты

CWE-670