← Back

CVE-2011-1491

nvd nist
Published: Apr 8, 2011Modified: Apr 29, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:P/I:N/A:N
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

The login form in Roundcube Webmail before 0.5.1 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then compose an e-mail message, related to a "login CSRF" issue.

Affected (22)

Products: Roundcube: Webmail
1 product
Webmail
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
Roundcube
Up to 0.5
Version 0.1.1
Version 0.1
Version 0.1 alpha
Version 0.1 beta2
Version 0.1 beta
Version 0.1 rc1
Version 0.1 rc2
Version 0.2.1
Version 0.2
Version 0.2 alpha
Version 0.2 beta
Version 0.3.1
Version 0.3
Version 0.3 beta
Version 0.3 rc1
Version 0.4.1
Version 0.4.2
Version 0.4
Version 0.4 beta
Version 0.5 beta
Version 0.5 rc

References (12)

Source: secalert@redhat.com
Patch
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.