aselfhosted·Selfhostedbyatzanteol Roundcube Webmail Flaws Allow Hackers to Steal Emails and PasswordsIf you're self hosting roundcube be sure to update.https://thehackernews.com/2024/08/roundcube-webmail-flaws-allow-hackers.html?m=1Open linkView original on sh.itjust.works91Comments4
sshadowbert lemmy.world2Hide 2 repliesIt's only if you view a specifically crafted email in the web client... still worth upgrading of course.2
aatzanteol replysh.itjust.works1Hide 1 replyOnly? "Viewing emails in a web browser" is the entire point of roundcube. It's trivial to send out millions of "specially created emails" looking for a victim.6
sshadowbert replylemmy.worldTrue, but it presumably would still require the user to open them. But, I was mostly worried that just having the server installed would be enough.3
I'm not surprised. A cube can't be round. That's an obvious design flaw.
It's only if you view a specifically crafted email in the web client... still worth upgrading of course.
Only? "Viewing emails in a web browser" is the entire point of roundcube. It's trivial to send out millions of "specially created emails" looking for a victim.
True, but it presumably would still require the user to open them.
But, I was mostly worried that just having the server installed would be enough.