// For flags

CVE-2011-1492

 

Severity Score

5.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is an expected request for an external Cascading Style Sheets (CSS) stylesheet, which allows remote authenticated users to trigger arbitrary outbound TCP connections from the server, and possibly obtain sensitive information, via a crafted request.

steps/utils/modcss.inc en Roundcube Webmail anterior a v0.5.1 no comprueba correctamente que una solicitud es una solicitud esperada para una hoja de estilo externa (Cascading Style Sheets), permitiendo a usuarios remotos autenticados lanzar conexiones arbitrarias salientes TCP desde el servidor , y posiblemente obtener información sensible, a través de una solicitud manipulada.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-03-21 CVE Reserved
  • 2011-04-08 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
<= 0.5
Search vendor "Roundcube" for product "Webmail" and version " <= 0.5"
-
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.1
Search vendor "Roundcube" for product "Webmail" and version "0.1"
-
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.1
Search vendor "Roundcube" for product "Webmail" and version "0.1"
alpha
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.1
Search vendor "Roundcube" for product "Webmail" and version "0.1"
beta
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.1
Search vendor "Roundcube" for product "Webmail" and version "0.1"
beta2
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.1
Search vendor "Roundcube" for product "Webmail" and version "0.1"
rc1
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.1
Search vendor "Roundcube" for product "Webmail" and version "0.1"
rc2
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.1.1
Search vendor "Roundcube" for product "Webmail" and version "0.1.1"
-
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.2
Search vendor "Roundcube" for product "Webmail" and version "0.2"
-
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.2
Search vendor "Roundcube" for product "Webmail" and version "0.2"
alpha
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.2
Search vendor "Roundcube" for product "Webmail" and version "0.2"
beta
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.2.1
Search vendor "Roundcube" for product "Webmail" and version "0.2.1"
-
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.3
Search vendor "Roundcube" for product "Webmail" and version "0.3"
-
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.3
Search vendor "Roundcube" for product "Webmail" and version "0.3"
beta
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.3
Search vendor "Roundcube" for product "Webmail" and version "0.3"
rc1
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.3.1
Search vendor "Roundcube" for product "Webmail" and version "0.3.1"
-
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.4
Search vendor "Roundcube" for product "Webmail" and version "0.4"
-
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.4
Search vendor "Roundcube" for product "Webmail" and version "0.4"
beta
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.4.1
Search vendor "Roundcube" for product "Webmail" and version "0.4.1"
-
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.4.2
Search vendor "Roundcube" for product "Webmail" and version "0.4.2"
-
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.5
Search vendor "Roundcube" for product "Webmail" and version "0.5"
beta
Affected
Roundcube
Search vendor "Roundcube"
Webmail
Search vendor "Roundcube" for product "Webmail"
0.5
Search vendor "Roundcube" for product "Webmail" and version "0.5"
rc
Affected