An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.
| Vendor | Product | Versions |
|---|---|---|
| roundcube | webmail | 1.6.0, 1.6.13 |
Updated affected versions to include 1.6.13, changed severity to HIGH, and noted that no exploit exists.
Initial creation