Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Roundcube XSS chained with cookie tossing for full inbox access

Summary

Aikido's AI pentesting agents found a stored XSS in Roundcube's display-attachment endpoint, chained with cookie tossing to hijack webmail sessions and accounts tied to that email. Fixed in 1.6.14.
Published
Collected

original ↗

Related coverage

back