3.5
CVSSv2

CVE-2011-1491

Published: 08/04/2011 Updated: 17/08/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

The login form in Roundcube Webmail prior to 0.5.1 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then compose an e-mail message, related to a "login CSRF" issue.

Vulnerable Product Search on Vulmon Subscribe to Product

roundcube webmail 0.1.1

roundcube webmail 0.1

roundcube webmail 0.2

roundcube webmail 0.4.1

roundcube webmail 0.4.2

roundcube webmail 0.2.1

roundcube webmail 0.4

roundcube webmail 0.3

roundcube webmail 0.3.1

roundcube webmail 0.5

roundcube webmail