Vector: | Remote |
Severity: | High |
Patch: | Unpatched |
Impact: |
Sensitive Information Leak System Information Leak |
Software: | RoundCube Webmail 0.x , vulnerable versions: <=0.8.5 |
Vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a logic error when sending email messages. A remote attacker can attach abritrary local file to an email using directory traversal sequencesand send it to arbitrary address.