EXPOSURES › CVE-2017-16651
CVE-2017-16651
HIGH ⌖ ON CISA KEV · EXPLOITEDRoundcube Webmail's default file-based attachment plugins suffered a file disclosure vulnerability due to insufficient input validation, exposing sensitive data on over 84,000 servers.
The vulnerability allowed attackers to read arbitrary files on the server, leading to potential data breaches and compliance violations. DIB organizations must ensure all default plugins are reviewed and patched, as reliance on unpatched defaults is a common failure point.
Shame score — The failure involved default plugins that were unpatched and actively exploited, exposing sensitive data on a massive scale.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default.
"Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default."