roundcube CVE Vulnerabilities & Metrics

Focus on roundcube vulnerabilities and metrics.

Last updated: 14 May 2025, 22:25 UTC

About roundcube Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with roundcube. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total roundcube CVEs: 48
Earliest CVE date: 20 Dec 2005, 02:03 UTC
Latest CVE date: 05 Aug 2024, 19:15 UTC

Latest CVE reference: CVE-2024-42009

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 5

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 66.67%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 66.67%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical roundcube CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.45

Max CVSS: 10.0

Critical CVEs (≥9): 2

CVSS Range vs. Count

Range Count
0.0-3.9 16
4.0-6.9 46
7.0-8.9 5
9.0-10.0 2

CVSS Distribution Chart

Top 5 Highest CVSS roundcube CVEs

These are the five CVEs with the highest CVSS scores for roundcube, sorted by severity first and recency.

All CVEs for roundcube

CVE-2024-42009 roundcube vulnerability CVSS: 0 05 Aug 2024, 19:15 UTC

A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.

CVE-2024-42008 roundcube vulnerability CVSS: 0 05 Aug 2024, 19:15 UTC

A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.

CVE-2024-37385 roundcube vulnerability CVSS: 0 07 Jun 2024, 04:15 UTC

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.

CVE-2024-37384 roundcube vulnerability CVSS: 0 07 Jun 2024, 04:15 UTC

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.

CVE-2024-37383 roundcube vulnerability CVSS: 0 07 Jun 2024, 04:15 UTC

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

CVE-2023-47272 roundcube vulnerability CVSS: 0 06 Nov 2023, 00:15 UTC

Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).

CVE-2023-5631 roundcube vulnerability CVSS: 0 18 Oct 2023, 15:15 UTC

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.

CVE-2023-43770 roundcube vulnerability CVSS: 0 22 Sep 2023, 06:15 UTC

Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.

CVE-2021-44026 roundcube vulnerability CVSS: 7.5 19 Nov 2021, 04:15 UTC

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

CVE-2021-44025 roundcube vulnerability CVSS: 4.3 19 Nov 2021, 04:15 UTC

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.

CVE-2020-18671 roundcube vulnerability CVSS: 3.5 24 Jun 2021, 19:15 UTC

Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php.

CVE-2020-18670 roundcube vulnerability CVSS: 3.5 24 Jun 2021, 19:15 UTC

Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php.

CVE-2021-26925 roundcube vulnerability CVSS: 3.5 09 Feb 2021, 09:15 UTC

Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.

CVE-2020-35730 roundcube vulnerability CVSS: 4.3 28 Dec 2020, 20:15 UTC

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.

CVE-2020-16145 roundcube vulnerability CVSS: 4.3 12 Aug 2020, 13:15 UTC

Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.

CVE-2020-15562 roundcube vulnerability CVSS: 4.3 06 Jul 2020, 12:15 UTC

An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists.

CVE-2020-13965 roundcube vulnerability CVSS: 4.3 09 Jun 2020, 03:15 UTC

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.

CVE-2020-13964 roundcube vulnerability CVSS: 4.3 09 Jun 2020, 03:15 UTC

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.

CVE-2020-12641 roundcube vulnerability CVSS: 7.5 04 May 2020, 15:15 UTC

rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

CVE-2020-12640 roundcube vulnerability CVSS: 7.5 04 May 2020, 15:15 UTC

Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.

CVE-2020-12626 roundcube vulnerability CVSS: 4.3 04 May 2020, 02:15 UTC

An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.

CVE-2020-12625 roundcube vulnerability CVSS: 4.3 04 May 2020, 02:15 UTC

An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.

CVE-2019-15237 roundcube vulnerability CVSS: 4.3 20 Aug 2019, 01:15 UTC

Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.

CVE-2019-10740 roundcube vulnerability CVSS: 4.3 07 Apr 2019, 15:29 UTC

In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker.

CVE-2018-19206 roundcube vulnerability CVSS: 4.3 12 Nov 2018, 17:29 UTC

steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment.

CVE-2018-19205 roundcube vulnerability CVSS: 5.0 12 Nov 2018, 17:29 UTC

Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.

CVE-2017-17688 roundcube vulnerability CVSS: 4.3 16 May 2018, 19:29 UTC

The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification

CVE-2018-9846 roundcube vulnerability CVSS: 6.8 07 Apr 2018, 21:29 UTC

In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plugin.move2archive request) to perform an MX (IMAP) injection attack by placing an IMAP command after a %0d%0a sequence. NOTE: this is less easily exploitable in 1.3.4 and later because of a Same Origin Policy protection mechanism.

CVE-2018-1000071 roundcube vulnerability CVSS: 5.0 13 Mar 2018, 15:29 UTC

roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity.

CVE-2017-16651 roundcube vulnerability CVSS: 4.6 09 Nov 2017, 14:29 UTC

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.

CVE-2015-5383 roundcube vulnerability CVSS: 5.0 23 May 2017, 04:29 UTC

Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) logs directory.

CVE-2015-5382 roundcube vulnerability CVSS: 4.0 23 May 2017, 04:29 UTC

program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.

CVE-2015-5381 roundcube vulnerability CVSS: 4.3 23 May 2017, 04:29 UTC

Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.

CVE-2017-8114 roundcube vulnerability CVSS: 6.5 29 Apr 2017, 19:59 UTC

Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.

CVE-2016-4068 roundcube vulnerability CVSS: 4.3 13 Apr 2017, 14:59 UTC

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.

CVE-2015-8864 roundcube vulnerability CVSS: 4.3 13 Apr 2017, 14:59 UTC

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-4068.

CVE-2017-6820 roundcube vulnerability CVSS: 4.3 12 Mar 2017, 05:59 UTC

rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element.

CVE-2015-2181 roundcube vulnerability CVSS: 6.5 30 Jan 2017, 22:59 UTC

Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via the (1) password or (2) username.

CVE-2015-2180 roundcube vulnerability CVSS: 9.0 30 Jan 2017, 22:59 UTC

The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.

CVE-2016-4552 roundcube vulnerability CVSS: 4.3 20 Dec 2016, 22:59 UTC

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message.

CVE-2016-9920 roundcube vulnerability CVSS: 6.0 08 Dec 2016, 18:59 UTC

steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message.

CVE-2016-4069 roundcube vulnerability CVSS: 6.8 25 Aug 2016, 18:59 UTC

Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service (disk consumption) via unspecified vectors.

CVE-2015-8794 roundcube vulnerability CVSS: 4.0 29 Jan 2016, 19:59 UTC

Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via a full pathname in the _alt parameter, related to contact photo handling.

CVE-2015-8793 roundcube vulnerability CVSS: 4.3 29 Jan 2016, 19:59 UTC

Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter in a mail task to the default URL, a different vulnerability than CVE-2011-2937.

CVE-2015-8770 roundcube vulnerability CVSS: 6.0 29 Jan 2016, 19:59 UTC

Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.

CVE-2015-8105 roundcube vulnerability CVSS: 3.5 10 Nov 2015, 17:59 UTC

Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name in a drag-n-drop file upload.

CVE-2015-1433 roundcube vulnerability CVSS: 4.3 03 Feb 2015, 16:59 UTC

program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.

CVE-2014-9587 roundcube vulnerability CVSS: 6.8 15 Jan 2015, 15:59 UTC

Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to (1) address book operations or the (2) ACL or (3) Managesieve plugins.

CVE-2013-1904 roundcube vulnerability CVSS: 5.0 08 Feb 2014, 00:55 UTC

Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers to read arbitrary files via a full pathname in the _value parameter for the generic_message_footer setting in a save-perf action to index.php, as exploited in the wild in March 2013.

CVE-2013-6172 roundcube vulnerability CVSS: 7.5 05 Nov 2013, 18:55 UTC

steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read arbitrary files, conduct SQL injection attacks, and execute arbitrary code.

CVE-2013-5646 roundcube vulnerability CVSS: 3.5 29 Aug 2013, 12:07 UTC

Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows remote authenticated users to inject arbitrary web script or HTML via the Name field of an addressbook group.

CVE-2013-5645 roundcube vulnerability CVSS: 4.3 29 Aug 2013, 12:07 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before 0.9.3 allow user-assisted remote attackers to inject arbitrary web script or HTML via the body of a message visited in (1) new or (2) draft mode, related to compose.inc; and (3) might allow remote authenticated users to inject arbitrary web script or HTML via an HTML signature, related to save_identity.inc.

CVE-2012-6121 roundcube vulnerability CVSS: 4.3 24 Feb 2013, 21:55 UTC

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.8.5 allows remote attackers to inject arbitrary web script or HTML via a (1) data:text or (2) vbscript link.

CVE-2012-4668 roundcube vulnerability CVSS: 4.3 25 Aug 2012, 10:29 UTC

Cross-site scripting (XSS) vulnerability in Roundcube Webmail 0.8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the signature in an email.

CVE-2012-3508 roundcube vulnerability CVSS: 4.3 25 Aug 2012, 10:29 UTC

Cross-site scripting (XSS) vulnerability in program/lib/washtml.php in Roundcube Webmail 0.8.0 allows remote attackers to inject arbitrary web script or HTML by using "javascript:" in an href attribute in the body of an HTML-formatted email.

CVE-2012-3507 roundcube vulnerability CVSS: 2.6 25 Aug 2012, 10:29 UTC

Cross-site scripting (XSS) vulnerability in program/steps/mail/func.inc in RoundCube Webmail before 0.8.0, when using the Larry skin, allows remote attackers to inject arbitrary web script or HTML via the email message subject.

CVE-2012-1253 roundcube vulnerability CVSS: 2.6 04 Jun 2012, 15:55 UTC

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.7, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via vectors involving an embedded image attachment.

CVE-2011-4078 roundcube vulnerability CVSS: 5.0 03 Nov 2011, 15:55 UTC

include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an arbitrary URL, and cause a denial of service (resource consumption and inbox outage), via a Subject header containing only a URL, a related issue to CVE-2011-3379.

CVE-2011-2937 roundcube vulnerability CVSS: 4.3 21 Sep 2011, 16:55 UTC

Cross-site scripting (XSS) vulnerability in the UI messages functionality in Roundcube Webmail before 0.5.4 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.

CVE-2011-1492 roundcube vulnerability CVSS: 5.5 08 Apr 2011, 15:17 UTC

steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is an expected request for an external Cascading Style Sheets (CSS) stylesheet, which allows remote authenticated users to trigger arbitrary outbound TCP connections from the server, and possibly obtain sensitive information, via a crafted request.

CVE-2011-1491 roundcube vulnerability CVSS: 3.5 08 Apr 2011, 15:17 UTC

The login form in Roundcube Webmail before 0.5.1 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then compose an e-mail message, related to a "login CSRF" issue.

CVE-2010-0464 roundcube vulnerability CVSS: 5.0 29 Jan 2010, 18:30 UTC

Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests.

CVE-2009-4077 roundcube vulnerability CVSS: 6.8 25 Nov 2009, 22:00 UTC

Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that send arbitrary emails via unspecified vectors, a different vulnerability than CVE-2009-4076.

CVE-2009-4076 roundcube vulnerability CVSS: 6.8 25 Nov 2009, 22:00 UTC

Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that modify user information via unspecified vectors, a different vulnerability than CVE-2009-4077.

CVE-2009-0413 roundcube vulnerability CVSS: 4.3 03 Feb 2009, 23:30 UTC

Cross-site scripting (XSS) vulnerability in RoundCube Webmail (roundcubemail) 0.2 stable allows remote attackers to inject arbitrary web script or HTML via the background attribute embedded in an HTML e-mail message.

CVE-2008-5620 roundcube vulnerability CVSS: 7.8 17 Dec 2008, 02:30 UTC

RoundCube Webmail (roundcubemail) before 0.2-beta allows remote attackers to cause a denial of service (memory consumption) via crafted size parameters that are used to create a large quota image.

CVE-2008-5619 roundcube vulnerability CVSS: 10.0 17 Dec 2008, 02:30 UTC

html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is processed by the preg_replace function with the eval switch.

CVE-2007-6321 roundcube vulnerability CVSS: 4.3 12 Dec 2007, 01:46 UTC

Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2, 2007-12-09, and earlier versions, when using Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via style sheets containing expression commands.

CVE-2005-4368 roundcube vulnerability CVSS: 5.0 20 Dec 2005, 02:03 UTC

roundcube webmail Alpha, with a default high verbose level ($rcmail_config['debug_level'] = 1), allows remote attackers to obtain the full path of the application via an invalid_task parameter, which leaks the path in an error message.