CISA Known Exploited Vulnerability

CVE-2017-16651

Roundcube · Roundcube Webmail

Roundcube Webmail File Disclosure Vulnerability

Date added
BOD 22-01 due date
CWE CWE-552
Ransomware Unknown

CISA description

Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default.

Required action

Apply updates per vendor instructions.