Description
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
Remediation
References
Related Vulnerabilities
WordPress Plugin Simple Job Board Directory Traversal (2.9.3)
WordPress Plugin s2Member Framework 's2_invoice' Parameter Remote Security Bypass (111105)
XWiki Inadequate Encryption Strength Vulnerability (CVE-2022-29161)
MySQL CVE-2014-2419 Vulnerability (CVE-2014-2419)
MediaWiki Incorrect Authorization Vulnerability (CVE-2021-36132)