FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Roundcube -- Multiple vulnerabilities

Affected packages
roundcube < 1.4.12,1

Details

VuXML ID 42a4d82d-4603-11ec-8be6-d4c9ef517024
Discovery 2021-11-12
Entry 2021-11-15

The Roundcube project reports:

XSS issue in handling attachment filename extension in mimetype mismatch warning

possible SQL injection via some session variables

References

URL https://roundcube.net/news/2021/11/12/security-updates-1.4.12-and-1.3.17-released