CyberRota Analysis
AI-GeneratedRoundcube Webmail versions prior to 1.6.18 and 1.7.x before 1.7.3 are vulnerable to IMAP command injection due to a mail search and LITERAL+ byte-count desynchronization issue, which could result in information disclosure or privilege escalation. Organizations using these versions should prioritize patching to mitigate the risk of unauthorized access and data leakage. This vulnerability is particularly critical for email service providers and enterprises relying on Roundcube for secure communications.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.
Related CVEs
Other vulnerabilities affecting the same vendor(s)