Roundcube vulnerabilities ?
I can't tell if this is a rehash of what i posted last month (and cPanel released updates for), or if this is new, since I'm seeing any CVE information.
https://cybersecuritynews.com/roundcube-1-6-18-and-1-7-3-released-with-fix/
Roundcube has released versions 1.6.18 and 1.7.3 to address eleven security vulnerabilities affecting its webmail platform. The updates fix a remote code execution flaw, server-side request forgery bypasses, injection vulnerabilities, and stored cross-site scripting issues.
Administrators using Roundcube 1.6.x or 1.7.x should update as soon as possible. The most serious issue is a remote code execution vulnerability in the markasjunk plugin. The flaw affects the plugin’s cmd_learn driver, which is used to send messages to a spam-learning backend.
-
Hey hey! We've got case CPANEL-55658 which is done so it will be included in the next build. I'm guessing tomorrow, but unofficially, that is just a guess.
0
Please sign in to leave a comment.
Comments
1 comment