Roundcube Webmail Vulnerability Let Attackers Track Email Opens
ID: b9641bc9-b312-57fc-ae99-6b642e7b79c2
STIX ID: report--b9641bc9-b312-57fc-ae99-6b642e7b79c2
Feed Name: cybersecurityNews.com
Threat Score
Roundcube Webmail versions prior to 1.5.13 and 1.6.x prior to 1.6.13 contain a privacy-bypass vulnerability: the HTML sanitizer failed to treat the SVG filter primitive <feImage> as an image attribute, allowing remote-image fetches to bypass "Block remote images" settings; attackers can embed a 1×1 SVG to confirm addresses, log recipient IPs, and fingerprint devices. Maintainers released fixes in versions 1.5.13 and 1.6.13 and administrators are urged to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
