Roundcube Webmail
cpe:2.3:a:roundcube:roundcube:*:*:*:*:*:*:*, +2 more
- >= 1.6, < 1.6.16
- >= 1.7, < 1.7.1
A vulnerability exists in Roundcube Webmail versions 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1, allowing the remote image blocking feature to be bypassed. This is achieved by using a specially crafted CSS var() value in an email message, which could lead to information disclosure or an access control bypass.
Exploitation of this vulnerability can result in a bypass of the remote image blocking feature, potentially allowing for unauthorized access to blocked images or information.
The vulnerability can be reproduced by sending an email that includes a CSS style with a var() function referencing a URL. When the email is received and the CSS is processed, the image blocking is bypassed, and the referenced image is loaded, despite the remote image blocking feature being enabled.
Users are advised to update to Roundcube Webmail versions 1.6.16 or 1.7.1.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.