Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-57004: XSS #9767

Open
2 tasks done
apoleon opened this issue Feb 8, 2025 · 1 comment
Open
2 tasks done

CVE-2024-57004: XSS #9767

apoleon opened this issue Feb 8, 2025 · 1 comment

Comments

@apoleon
Copy link

apoleon commented Feb 8, 2025

Prerequisites

  • I have searched for duplicate or closed issues
  • I can recreate the issue with all plugins disabled

Describe the issue

CVE-2024-57004 has been assigned for a security problem in roundcube 1.6.9, apparently a XSS vulnerability. I can't find any information about it in your Git repository. Are you aware of the problem already? If yes, can you elaborate on the problem and point me to your fixing commit?

https://github.com/riya98241/CVE/blob/main/CVE-2024-57004

https://www.cve.org/CVERecord?id=CVE-2024-57004

What browser(s) are you seeing the problem on?

Firefox

What version of PHP are you using?

No response

What version of Roundcube are you using?

1.6.9

JavaScript errors

No response

PHP errors

No response

@alecpl
Copy link
Member

alecpl commented Feb 8, 2025

Sounds like one of these PDF viewer problems Roundcube can do not much about. This is a browser issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants