CRITICAL

CVE-2021-44026

Fedoraproject Fedora 2021-11-19 CVSS v3.1
CVSS
9.8
KEV

Description

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

Summary dbcve.org

SQL injection vulnerability in Roundcube Webmail's search and search_params functionality, affecting versions before 1.3.17 and 1.4.x before 1.4.12. The flaw allows crafted input through search parameters to manipulate underlying database queries, potentially leading to data exfiltration or unauthorized access, with a CVSS 9.8 indicating remote, low-complexity exploitation likely without authentication.

Mitigation

Upgrade Roundcube to version 1.3.17 or 1.4.12 (or later) immediately. Verify all plugins and custom integrations are compatible with the patched release.

Patch Commit

Weakness (CWE)

CWE-89 SQL Injection

EPSS Score

69.88%
Probability of exploitation in next 30 days
99.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE