CVE-2025-68460

7.2

Roundcube · Webmail

Roundcube Webmail versions prior to 1.5.12 and 1.6.12 are susceptible to an information disclosure vulnerability within the HTML style sanitizer.

Executive summary

A critical information disclosure vulnerability in Roundcube Webmail allows unauthenticated attackers to bypass HTML sanitization, potentially exposing sensitive user data.

Vulnerability

The application fails to properly encode or escape output within the HTML style sanitizer (CWE-116). This flaw allows an unauthenticated attacker to manipulate sanitized content, potentially leading to unauthorized information disclosure.

Business impact

The vulnerability carries a CVSS score of 7.2, reflecting a high risk due to the lack of required authentication and the potential for remote exploitation. Successful exploitation could lead to the exposure of sensitive user data, undermining the confidentiality of communications and potentially resulting in significant reputational damage or regulatory non-compliance for organizations relying on the platform.

Remediation

Immediate Action: Administrators must update their Roundcube Webmail installations to version 1.5.12 or 1.6.12 immediately to incorporate the security patches provided by the vendor.

Proactive Monitoring: Security teams should review web server access logs for anomalous requests directed at the HTML rendering or preview components of the application.

Compensating Controls: Deploying a Web Application Firewall (WAF) with updated rulesets to filter malicious HTML payloads can provide temporary protection while the patching process is completed.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the ease of exploitation and the potential for unauthorized data access, this vulnerability poses a significant risk to organizational privacy. System administrators are strongly advised to prioritize the application of the vendor-provided patches. Failure to remediate this issue promptly leaves the webmail environment exposed to potential information harvesting attacks.

More Roundcube CVEs

Sources