Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-68460

Опубликовано: 18 дек. 2025
Источник: redhat
CVSS3: 5.4

Описание

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

A flaw was found in Roundcube Webmail. This information disclosure vulnerability resides within the HTML style sanitizer, potentially allowing an attacker to gain unauthorized access to sensitive information. The vulnerability is triggered by improper handling of HTML styles.

Отчет

This vulnerability is rated Low for Red Hat. The information disclosure flaw in Roundcube Webmail's HTML style sanitizer requires user interaction to exploit, limiting its impact in typical Red Hat deployments.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-116
https://bugzilla.redhat.com/show_bug.cgi?id=2423487roundcubemail: Roundcube Webmail: Information Disclosure via HTML Style Sanitizer

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.2
ubuntu
4 месяца назад

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

CVSS3: 7.2
nvd
4 месяца назад

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

CVSS3: 7.2
debian
4 месяца назад

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a in ...

CVSS3: 7.2
github
4 месяца назад

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

CVSS3: 7.2
fstec
4 месяца назад

Уязвимость модуля проверки стилей HTML почтового клиента RoundCube Webmail, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

5.4 Medium

CVSS3