Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS) and other vulnerabilities. The XSS issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page. Additional vulnerabilities include an infinite loop in TNEF (winmail.dat) decoder and vulnerabilities in the password plugin.
| Vendor | Product | Versions |
|---|---|---|
| Roundcube | Webmail | 1.6.0, 1.7.0 |
Added details about TNEF decoder infinite loop and password plugin vulnerabilities, plus new tags for TNEF and password-plugin.
Updated affected versions to include 1.6.16 and 1.7.1, changed severity to HIGH, and noted that the vulnerability is actively exploited.
Initial creation