CVE-2024-42009: RoundCube Webmail Cross-Site Scripting Vulnerability.
RoundCube Webmail Cross-Site Scripting Vulnerability. RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
- CISA KEV-listed (remediation due 2025-06-30)
- EPSS 91.4% (99.7% percentile)