Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-roundcubemail | Oct 1, 2024 | Apr 29, 2017 | |
| Debian | debian-upgrade-roundcube | May 7, 2017 | Apr 29, 2017 | |
| Freebsd | freebsd-upgrade-package-roundcube | Jun 9, 2017 | Jun 9, 2017 | |
| Gentoo Linux | gentoo-linux-upgrade-mail-client-roundcube | Oct 30, 2017 | Apr 29, 2017 | |
| Suse | — | suse-upgrade-roundcubemail | May 15, 2017 | Apr 29, 2017 |
| Ubuntu | ubuntu-pro-upgrade-roundcube-coreubuntu-pro-upgrade-roundcube-plugins | Jun 26, 2025 | Apr 29, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub