Roundcube webmail Cross-Site Scripting Vulnerability (CVE-2015-8105)
Roundcube webmail Cross-Site Scripting Vulnerability (CVE-2015-8105)
Release date:
Updated on:
Affected Systems:
RoundCube Webmail <1.0.7
RoundCube Webmail 1.1.x-1.1.3
Description:
CVE (CAN) ID: CVE-2015-8105
RoundCube Webmail is a browser-based IMAP client.
Roundcube webmail versions earlier than 1.0.7, 1.1.x-1.1.3, and program/js/app. the cross-site scripting vulnerability exists in Javascript. remote authenticated users can inject arbitrary Web scripts or HTML files by dragging and dropping the file name uploaded.
<* Source: lightsey
*>
Suggestion:
Vendor patch:
RoundCube
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://trac.roundcube.net/changeset/dd7db2179/github
Http://trac.roundcube.net/ticket/1490530
This article permanently updates the link address: