Critical Roundcube Flaw Allows Attackers to Inject SQL Queries
ID: 5bed5523-bca8-53cc-8b4d-85cc3eb5317e
STIX ID: report--5bed5523-bca8-53cc-8b4d-85cc3eb5317e
Feed Name: Cyber Press
Roundcube Webmail released security updates (1.6.16 and 1.7.1) addressing eight vulnerabilities — most critically a pre-authentication SQL injection in the virtuser_query plugin that can execute arbitrary database queries without credentials and an LDAP autovalues code-evaluation flaw that could enable remote code execution; additional issues include XSS, CSS injection, SSRF bypasses, session poisoning enabling file deletion, and remote resource blocking bypasses. Administrators of internet-facing Roundcube instances should patch immediately, consider disabling the virtuser_query plugin if unused, audit logs for anomalous queries or sessions, and review LDAP settings to mitigate potential multi-stage exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
