Cross-Site Scripting vulnerability in Roundcube webmail allows attackers to steal and send emails via crafted email messages. Despite high CVSS score and CISA KEV listing, this is client-side XSS requiring user interaction, not direct server compromise.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: USER_INTERACTION
CVE Published: 2024-08-05
Added to CISA KEV: 2025-06-09 308 DAYS BETWEEN CVE AND KEV
CVE-2024-42009 is a critical Cross-Site Scripting (XSS) vulnerability affecting Roundcube Webmail [4].
The XSS vulnerability CVE-2024-42009 in Roundcube versions 1.6.7 and below, and 1.5.7 and below, allows unauthenticated attackers to steal emails and contacts, as well as send emails from a victim's account with critical severity. ... The XSS vulnerability CVE-2024-42009 in Roundcube versions 1.6.7โฆ
This repository contains a proof-of-concept (PoC) exploit for CVE-2024-42009 a stored Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail version 1.6.7 and other several versions. The exploit demonstrates how an attacker can inject malicious JavaScript in a message and take advantage of aโฆ
An official website of the United States government Here's how you know ... CVE-2024-42009 Detail. Description. A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abusโฆ
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim.
Roundcube XSS vulnerabilities (CVE-2024-42009, CVE-2024-42008) could be exploited to steal users' emails and contacts, and send emails.
When a victim views a malicious email in Roundcube sent by an attacker, the attacker can execute arbitrary JavaScript in the victim's browser.