Huy Nguyễn Phạm Nhật, and Valentin T. and Lutz Wolf of CrowdStrike, discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not correctly process and sanitize requests. This would allow an attacker to perform Cross-Side Scripting (XSS) attacks.
https://security-tracker.debian.org/tracker/DSA-5714-1
Continue reading...
https://security-tracker.debian.org/tracker/DSA-5714-1
Continue reading...

