Skip to content

RCE with custom label titles

High
mike-kfed published GHSA-wp6h-wgxq-v949 Oct 10, 2022

Package

roundcube-thunderbird_labels (roundcube-plugin)

Affected versions

<=1.4.12

Patched versions

None

Description

description

Remote code execution vulnerability in
roundcube-thunderbird_labels when tb_label_modify_labels is enabled.

workaround

If you cannot upgrade to roundcube-thunderbird_labels-1.4.13 disable the tb_label_modify_labels config option.

Severity

High

CVE ID

No known CVE

Weaknesses

Credits