CVE-2015-8794: Roundcube Webmail
Medium severity, CVSS 6.5. EPSS: 2.1% chance of exploitation in the next 30 days.
Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via a full pathname in the _alt parameter, related to contact photo handling.
Affected products
- Roundcube Roundcube Webmail: up to and including 1.0.5; version 1.1.0 only; version 1.1.1 only
Published 2016-01-29. Last modified 2026-06-17.