Описание
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.
Ссылки
EPSS
6.4 Medium
CVSS3
Дефекты
Связанные уязвимости
(In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa ...)
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa ...
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.
EPSS
6.4 Medium
CVSS3