Roundcube XSS chained with cookie tossing for full inbox access
aikido.dev | blog | #ai-security | #attack-chains | #web-security | #xss | #roundcube | #vulnerability-disclosure | #ai-pentesting | #session-hijacking | #csp-bypass | #webmail | #cookie-tossing
Summary
Aikido's AI pentesting agents found a stored XSS in Roundcube's display-attachment endpoint, chained with cookie tossing to hijack webmail sessions and accounts tied to that email. Fixed in 1.6.14.
- Published
- Collected
Skip to content