← Voltar à pesquisa de CVEs

CVE-2026-35538

Roundcube Webmail

Descrição

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

CVSS 3.1EPSS 0.28300000000000003%Risco 0.32
Ver fonte
Publicação
2026-04-03 05:16:21
Versões afetadas
<1.5.14, <1.6.14
Tipo
Installed app
Última alteração
2026-07-24 21:10:00
Vetor
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N