Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017
Published Nov 9, 2017 ·Due May 3, 2022
7.8
HIGHCVSS 3.1
EPSS 45.74%
Description
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.
Affected products
No data.
Configuration 1
- ≤ 1.1.9
- 1.2.0
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.4
- 1.2.5
- 1.2.6
- 1.3.0
- 1.3.1
- 1.3.2
Configuration 2
- 7.0
- 9.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:P/I:P/A:P
Date Added
Nov 3, 2021
Patch Due
May 3, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 4, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (34 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 45.74% (0.45742) | 98.77th | v5 (v2026.06.15) |
| Oct 1, 2026 | 45.74% (0.45742) | 98.76th | v5 (v2026.06.15) |
| Sep 20, 2026 | 36.67% (0.36668) | 98.43th | v5 (v2026.06.15) |
| Jul 14, 2026 | 36.92% (0.36919) | 98.33th | v5 (v2026.06.15) |
| Jun 15, 2026 | 42.83% (0.42831) | 98.54th | v5 (v2026.06.15) |
| May 29, 2026 | 35.94% (0.35939) | 97.16th | v4 (v2025.03.14) |
| May 22, 2026 | 39.26% (0.39262) | 97.35th | v4 (v2025.03.14) |
| Apr 22, 2026 | 37.27% (0.37271) | 97.19th | v4 (v2025.03.14) |
| Apr 3, 2026 | 33.31% (0.33307) | 96.89th | v4 (v2025.03.14) |
| Mar 25, 2026 | 35.23% (0.35232) | 97.00th | v4 (v2025.03.14) |
| Feb 28, 2026 | 37.82% (0.37820) | 97.12th | v4 (v2025.03.14) |
| Feb 21, 2026 | 36.42% (0.36420) | 97.02th | v4 (v2025.03.14) |
| Jan 30, 2026 | 38.27% (0.38274) | 97.11th | v4 (v2025.03.14) |
| Jan 27, 2026 | 33.35% (0.33353) | 96.79th | v4 (v2025.03.14) |
| Nov 23, 2025 | 30.22% (0.30221) | 96.47th | v4 (v2025.03.14) |
| Oct 22, 2025 | 33.35% (0.33353) | 96.69th | v4 (v2025.03.14) |
| Jun 11, 2025 | 30.53% (0.30531) | 96.45th | v4 (v2025.03.14) |
| Mar 30, 2025 | 28.32% (0.28317) | 96.09th | v4 (v2025.03.14) |
| Mar 29, 2025 | 40.03% (0.40034) | 95.98th | v4 (v2025.03.14) |
| Mar 28, 2025 | 28.32% (0.28317) | 96.09th | v4 (v2025.03.14) |
| Mar 27, 2025 | 40.03% (0.40034) | 96.85th | v4 (v2025.03.14) |
| Mar 20, 2025 | 34.37% (0.34369) | 96.66th | v4 (v2025.03.14) |
| Mar 19, 2025 | 40.03% (0.40034) | 96.90th | v4 (v2025.03.14) |
| Mar 17, 2025 | 34.37% (0.34369) | 96.61th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.42% (0.01423) | 87.06th | v3 (v2023.03.01) |
| Sep 7, 2023 | 1.48% (0.01484) | 85.22th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.42% (0.00416) | 70.04th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.80% (0.04804) | 89.26th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.80% (0.04804) | 88.20th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.80% (0.04804) | 74.65th | v2 (v2022.01.01) |
| Feb 3, 2022 | 9.15% (0.09152) | 86.58th | v1 |
| Jan 6, 2022 | 9.15% (0.09152) | 86.43th | v1 |
| Sep 1, 2021 | 9.15% (0.09152) | 93.82th | v1 |
| Apr 14, 2021 | 9.15% (0.09152) | 0.00th | v1 |
References (10)
- http://packetstormsecurity.com/files/161226/Roundcube-Webmail-1.2-File-Disclosure.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/101793 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://github.com/roundcube/roundcubemail/issues/6026 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.10 x_refsource_CONFIRMIssue TrackingRelease NotesThird Party Advisory
- https://github.com/roundcube/roundcubemail/releases/tag/1.2.7 x_refsource_CONFIRMIssue TrackingRelease NotesThird Party Advisory
- https://github.com/roundcube/roundcubemail/releases/tag/1.3.3 x_refsource_CONFIRMIssue TrackingRelease NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2017/11/msg00039.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://roundcube.net/news/2017/11/08/security-updates-1.3.3-1.2.7-and-1.1.10 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-16651 government-resourceUS Government Resource
- https://www.debian.org/security/2017/dsa-4030 vendor-advisoryx_refsource_DEBIANIssue TrackingThird Party Advisory
Change history (0)
No recorded changes yet.