Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/98445 | Third Party Advisory VDB Entry |
https://github.com/ilsani/rd/tree/master/security-advisories/web/roundcube/cve-2017-8114 | Exploit Third Party Advisory |
https://roundcube.net/news/2017/04/28/security-updates-1.2.5-1.1.9-and-1.0.11 | Release Notes Vendor Advisory |
https://security.gentoo.org/glsa/201707-11 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2017-04-29 19:59
Updated : 2024-02-04 19:11
NVD link : CVE-2017-8114
Mitre link : CVE-2017-8114
CVE.ORG link : CVE-2017-8114
JSON object : View
Products Affected
roundcube
- webmail
CWE
CWE-269
Improper Privilege Management