Roundcube Webmail Flaws Allow Hackers to Steal Emails and Passwords

atzanteol@sh.itjust.works to Selfhosted@lemmy.world – 93 points –
Roundcube Webmail Flaws Allow Hackers to Steal Emails and Passwords
thehackernews.com

If you're self hosting roundcube be sure to update.

4

You are viewing a single comment

It's only if you view a specifically crafted email in the web client... still worth upgrading of course.

Only? "Viewing emails in a web browser" is the entire point of roundcube. It's trivial to send out millions of "specially created emails" looking for a victim.

True, but it presumably would still require the user to open them.

But, I was mostly worried that just having the server installed would be enough.