V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2014-9587
DEB
Medium

Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentic…

CVSS
6.8
Medium
EPSS
0.02
p79
Published
2014-01-01
Updated
2014-01-01
Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to (1) address book operations or the (2) ACL or (3) Managesieve plugins.

Tags · CWE
CWE-352
CAPEC-62
CAPEC-111
CAPEC-462
CAPEC-467
Affected products
Webmail ≤ 1.0.3
CVSS vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Timeline
2014-01-01
Published
2014-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.021 · p79
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
roundcubeTracked
roundcubeTracked
roundcubeTracked
roundcubeTracked
roundcubeTracked
roundcubeTracked
roundcubeTracked
roundcubeTracked
roundcubeTracked
roundcubeTracked
roundcubeTracked
roundcubeTracked
roundcubeTracked
roundcubeTracked
webmail*Tracked
Source databases
DEB
CVE
UBU