SQL Injection Vulnerability in Roundcube Webmail (Versions 1.3.17 and below, 1.4.x and below)

SQL Injection Vulnerability in Roundcube Webmail (Versions 1.3.17 and below, 1.4.x and below)

CVE-2021-44026 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

Learn more about our Cis Benchmark Audit For Microsoft Sql Server.