CVE-2011-1491
EPSS 0.39%
Description
The login form in Roundcube Webmail before 0.5.1 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then compose an e-mail message, related to a "login CSRF" issue.
How to fix CVE-2011-1491
To remediate CVE-2011-1491, upgrade the affected package to a fixed version below.
- Debian/roundcube—upgrade to 0.5.1-1 or later
Is CVE-2011-1491 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.5.1-1