Release date:
Updated on:
Affected Systems:
RoundCube Webmail <0.9.3
Description:
--------------------------------------------------------------------------------
RoundCube Webmail is a browser-based IMAP client.
The "identity" configuration page of the earlier versions of RoundCube Webmail 0.9.3 has an XSS vulnerability. Some inputs passed to the "editing received mails as new" function are not properly filtered, this can be exploited to insert and execute arbitrary HTML and script code.
<* Source: Andrea Menin
Link: http://secunia.com/advisories/54536/
Http://trac.roundcube.net/ticket/1489251
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
RoundCube
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://roundcube.net/
Http://trac.roundcube.net/wiki/Changelog#RELEASE0.9.3
Http://trac.roundcube.net/ticket/1489251