unihostbrasil
Verified User
We just published new releases which fix a recently reported vulnerability that allows an attacker to overwrite configuration settings using user preferences. This can result in random file access, manipulated SQL queries and even code execution. The latter one only affects versions 0.8.6 and older.
More information about this vulnerability will be published under CVE-2013-6172.
http://roundcube.net/news/2013/10/21/security-updates-095-and-087/
More information about this vulnerability will be published under CVE-2013-6172.
http://roundcube.net/news/2013/10/21/security-updates-095-and-087/