Debian Roundcube Important CSS Injection Threat DSA-6137-1 CVE-2026-25916

User avatar
admin Verified Great Britain
Site Admin
Posts: 18673
Joined: Wed Jun 11, 2025 9:20 pm

Awards

Debian Roundcube Important CSS Injection Threat DSA-6137-1 CVE-2026-25916

Post by admin Verified »

CERT Polska and nullcathedral discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not correctly process and sanitize requests. This would allow an attacker to perform CSS injection attacks, or leak sensitive information. For the oldstable distribution (bookworm), these problems have been fixed

Source: https://linuxsecurity.com/advisories/de ... 2026-25916
Post Reply

Who is online

Users browsing this forum: No registered users and 0 guests