CVE-2024-42009
Description
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
In plain language
AI Act nowIf you run RoundCube Webmail version 1.5.7 or older (up to 1.5.7) or any 1.6.x up to 1.6.7, attackers can trick logged-in users into opening a crafted email and then steal their session and send emails on their behalf—this is actively exploited, so you should act.
CVE-2024-42009 is a Cross-Site Scripting (CWE-79) flaw in RoundCube Webmail where a remote attacker can deliver a crafted email that runs in the victim’s browser when they open it in Roundcube, enabling session theft and sending emails as the victim; CISA KEV confirms real-world exploitation.
What to do now
- Check whether your RoundCube Webmail version is 1.5.7 or earlier (up to 1.5.7) or any 1.6.x up through 1.6.7.
- If you are affected, upgrade RoundCube Webmail to 1.5.8 or 1.6.8 (use the vendor’s official updates).
- After upgrading, review recent webmail/account activity for evidence of suspicious message reads, session issues, or outbound emails that you did not send.
- If you cannot patch immediately, disable or restrict access to the affected webmail instance until updates are applied, and consider filtering/blocking suspicious inbound messages that could trigger the attack.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Уязвимости в Roundcube используются для слежки за ученымиru-ru·Хакер (xakep.ru)· Exploited Roundcube Webmail UNK_MassTraction
- Hackers exploit Roundcube flaw to spy on academic researchersen-us·BleepingComputer· Exploited Roundcube UNK_MassTraction
- Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universitiesen·The Hacker News· Exploited Roundcube webmail UNK_MassTraction
- FrostyNeighbor: Fresh mischief and digital shenanigansen·ESET WeLiveSecurity· Exploited PicassoLoader FrostyNeighbor
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2024-42009 and every CVE in our database. Create a free account — no credit card required.
Create Free Account