Skip to content
COOEY

EXPOSURES › CVE-2021-44026

CVE-2021-44026

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-06-22 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-44026 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Roundcube Webmail SQL Injection Vulnerability exposed in over 84,000 servers.

Roundcube Webmail is vulnerable to SQL injection via search or search_params, exposing over 84,000 servers to remote code execution. This is a high-severity vulnerability that can lead to data breaches and unauthorized access. DIB organizations should ensure their systems are patched and monitored for exploitation.

Shame score — Exposed over 84,000 servers to actively exploited remote code execution vulnerability.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Roundcube Webmail is vulnerable to SQL injection via search or search_params.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.