English - French - Italian


emails

Roundcube mail server fix

Peter • Thursday, August 8, 2024 • 1 min read (193)


The issue:

A critical Cross-Site Scripting (XSS) vulnerability was discovered in Roundcube, an open-source webmail software widely used by government agencies and universities.

Who and When:

Our note:

This is a good example of collaboration and reactiveness between researchers (Oskar Zeino-Mahmalat) and vendor (Aleksander Machniak) ! :)

Solution:

If you aree running Roundcube in version 1.6.7 and below, and in version 1.5.7 and below,
you need to follow Roundcube fix here https://roundcube.net/news/2024/08/04/security-updates-1.6.8-and-1.5.8

Credits: Sonar - vulnerability-in-roundcube-webmail
- CVE: CVE-2024-42008
- CVE: CVE-2024-42009



Simple CSS can be used to bypass anti-phishing Outlook warning...


New TLD is now reserved from ICANN for internal networks