Published:2007/11/19  Last Updated:2008/05/21

JVN#33820033
RoundCube Webmail cross-site request forgery vulnerability

Overview

RoundCube Webmail from the RoundCube Project contains a cross-site request forgery vulnerability.

Products Affected

  • RoundCube Releases 0.1-alpha to 0.1-RC1

Description

RoundCube Webmail is an open source webmail client from the RoundCube Project.
RoundCube Webmail contains a cross-site request forgery vulnerability that may allow disclosure of information such as email subject lines.

Impact

Information such as email subject lines may be disclosed on the web browser of a user who logged into RoundCube Webmail.

Solution

Update the Software
Apply the latest updates provided by the vendor.

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Analyzed on 2007.11.19

Measures Conditions Severity
Access Required Routed - can be attacked over the Internet using packets
  • High
Authentication None - anonymous or no authentication (IP addresses do not count)
  • High
User Interaction Required Simple - the user must be convinced to take a standard action that does not feel harmful to most users, such as click on a link or view a file
  • Medium
Exploit Complexity Low - little to no expertise and/or luck required to exploit (cross-site scripting)
  • High

Description of each analysis measures

Credit

Daiki Fukumori of Secure Sky Technology, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendors under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia JVNDB-2007-000805

Update History