CISA Known Exploited Vulnerability

CVE-2021-44026

Roundcube · Roundcube Webmail

Roundcube Webmail SQL Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-89
Ransomware Unknown

CISA description

Roundcube Webmail is vulnerable to SQL injection via search or search_params.

Required action

Apply updates per vendor instructions.