Critical XSS Vulnerability In Roundcube Let Attackers Execute Arbitrary Code
ID: b6512d4f-bf05-5bb9-a4c1-b5301b3d7755
STIX ID: report--b6512d4f-bf05-5bb9-a4c1-b5301b3d7755
Feed Name: cybersecurityNews.com
Threat Score
Roundcube webmail contains critical XSS vulnerabilities (CVE-2024-42009 — zero‑click; CVE-2024-42008 — single‑click) that have been exploited in the wild by the Winter Vivern APT to exfiltrate emails and steal credentials from government and military targets; administrators should urgently upgrade to patched versions (1.6.8 or 1.5.8) and affected users should change passwords and clear site data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
