Description
Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service (disk consumption) via unspecified vectors.
Remediation
References
Related Vulnerabilities
IBM RTC Exposure of Resource to Wrong Sphere Vulnerability (CVE-2020-4989)
WordPress Plugin BuddyPress Arbitrary File Deletion (2.7.3)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1155)
WordPress Plugin WP Portfolio Gallery Cross-Site Scripting (1.0.0)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-1167)