Debian Security Update DSA-4674 roundcube - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,885
Reaction score
74
Credits
-1,257
It was discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not correctly process and sanitize requests. This would allow a remote attacker to perform either a Cross-Site Request Forgery (CSRF) forcing an authenticated user to be logged out, or a Cross-Side Scripting (XSS) leading to execution of arbitrary code.

Continue reading...
 


Follow Linux.org

Staff online


Latest posts

Top