CVE-2015-5382: Roundcube Webmail
Medium severity, CVSS 6.5. EPSS: 2.9% chance of exploitation in the next 30 days.
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
Affected products
- Roundcube Roundcube Webmail: up to and including 1.0.5; version 1.1.1 only
- Roundcube Webmail: version 1.1 only
Published 2017-05-23. Last modified 2026-06-17.