CVE-2021-44026

CRITICAL9.8⚠ KEVEPSS 72.5%

Roundcube Webmail SQL Injection Vulnerability

發布日:2021/11/19修改日:2026/5/29加入 CISA KEV 日:2023/6/22

描述

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

參考連結(8)