CVE-2020-12626Cross-Site Request Forgery in Webmail

Severity
6.5MEDIUMNVD
OSV6.1
EPSS
1.3%
top 20.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 4
Latest updateAug 8

Description

An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

NVDroundcube/webmail< 1.4.4

Also affects: Debian Linux 10.0, 9.0

Patches

🔴Vulnerability Details

4
OSV
roundcube vulnerabilities2022-08-08
GHSA
GHSA-3q5x-3fpw-pfv9: An issue was discovered in Roundcube Webmail before 12022-05-24
OSV
CVE-2020-12626: An issue was discovered in Roundcube Webmail before 12020-05-04
CVEList
CVE-2020-12626: An issue was discovered in Roundcube Webmail before 12020-05-04

📋Vendor Advisories

5
Ubuntu
Roundcube Webmail vulnerabilities2022-08-08
Oracle
Oracle Oracle Insurance Applications Risk Matrix: Architecture (Apache POI) — CVE-2017-126262020-07-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (Apache POI) — CVE-2017-126262020-04-15
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache POI) — CVE-2017-126262020-01-15
Debian
CVE-2020-12626: roundcube - An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cau...2020

💬Community

3
Bugzilla
CVE-2020-12626 roundcubemail: CSRF attack can cause an authenticated user to be logged out because POST was not considered [fedora-all]2020-05-20
Bugzilla
CVE-2020-12626 roundcubemail: CSRF attack can cause an authenticated user to be logged out because POST was not considered [epel-all]2020-05-20
Bugzilla
CVE-2020-12626 roundcubemail: CSRF attack can cause an authenticated user to be logged out because POST was not considered2020-05-20
CVE-2020-12626 — Cross-Site Request Forgery in Webmail | cvebase