At the same time, it injects an unauthorized login form into the ... to exfiltrate messages from the mail server, the researchers say. CVE-2024-37383 affects Roundcube versions earlier than ...
It was closed in versions Roundcube 1.5.7 and 1.6.7 in May. The vulnerability allows attackers to execute JavaScript code in the context of users. The attacker mail used the decoded Javascript ...
Roundcube Webmail is a popular browser-based email client with a user-friendly ... It downloads a decoy .DOC file, while injecting an unauthorized login form into the HTML page, which requests ...