Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.
References
| Link | Resource |
|---|---|
| https://roundcube.net/news/2017/04/28/security-updates-1.2.5-1.1.9-and-1.0.11 | Release Notes Vendor Advisory |
| https://github.com/ilsani/rd/tree/master/security-advisories/web/roundcube/cve-2017-8114 | Exploit Third Party Advisory |
| https://security.gentoo.org/glsa/201707-11 | |
| http://www.securityfocus.com/bid/98445 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-04-29 19:59
Updated : 2019-10-03 00:03
NVD link : CVE-2017-8114
Mitre link : CVE-2017-8114
JSON object : View
Products Affected
roundcube
- webmail
- roundcube_webmail
CWE
CWE-269
Improper Privilege Management
