← Zurück zur CVE-Suche

CVE-2026-35538

Roundcube Webmail

Beschreibung

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

CVSS 3.1EPSS 0.28300000000000003%Risiko 0.32
Quelle öffnen
Veröffentlicht
2026-04-03 05:16:21
Betroffene Versionen
<1.5.14, <1.6.14
Typ
Installed app
Zuletzt geändert
2026-07-24 21:10:00
Vektor
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N