vulnerability
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
HighCVSS 8.8KEVEPSS 99%
Summary
A pre-authentication SQL injection vulnerability in Roundcube Webmail (versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1) is currently being actively exploited in the wild. Patches are available, but a significant number of vulnerable instances remain exposed online.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
