Vulnerability Description
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
CVSS v3.1 Score
6.4
MEDIUMVector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N1.2
Exploitability
5.2
Impact
Attack Vector Analysis
Attack Vector
NETWORKAttack Complexity
HIGHPrivileges Required
LOWUser Interaction
REQUIREDScope
UNCHANGEDConfidentiality
HIGHIntegrity
HIGHAvailability
NONEWeaknesses (CWE)1
Affected Configurations2
References & Resources7
Raw JSON Data