Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade roundcubemail | Oct 1, 2024 | Apr 29, 2017 |
| Debian | — | Upgrade roundcube | May 7, 2017 | Apr 29, 2017 |
| Freebsd | — | Upgrade roundcube | Jun 9, 2017 | Jun 9, 2017 |
| Gentoo Linux | — | Upgrade mail-client/roundcube. | Oct 30, 2017 | Apr 29, 2017 |
| Suse | — | Upgrade roundcubemail | May 15, 2017 | Apr 29, 2017 |
| Ubuntu | — | Upgrade roundcube-plugins (Ubuntu Pro)Upgrade roundcube-core (Ubuntu Pro) | Jun 26, 2025 | Apr 29, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub