← Retour à la recherche de CVE

CVE-2026-35538

Roundcube Webmail

Description

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

CVSS 3.1EPSS 0.28300000000000003%Risque 0.32
Voir la source
Publication
2026-04-03 05:16:21
Versions concernées
<1.5.14, <1.6.14
Type
Installed app
Dernière modification
2026-07-24 21:10:00
Vecteur
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N