Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.
References
Link | Resource |
---|---|
https://roundcube.net/news/2017/04/28/security-updates-1.2.5-1.1.9-and-1.0.11 | Release Notes Vendor Advisory |
https://github.com/ilsani/rd/tree/master/security-advisories/web/roundcube/cve-2017-8114 | Exploit Third Party Advisory |
https://security.gentoo.org/glsa/201707-11 | Third Party Advisory |
http://www.securityfocus.com/bid/98445 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2017-04-29 19:59
Updated : 2022-09-27 18:16
NVD link : CVE-2017-8114
Mitre link : CVE-2017-8114
JSON object : View
Products Affected
roundcube
- webmail
CWE
CWE-269
Improper Privilege Management