Back
Medium · CVSS 4.3Information Disclosure (CWE-200)

Roundcube Webmail Style Sanitizer can be bypassed using CSS Character Escapes

Vulnerability Summary

HackerOne disclosed report --> https://hackerone.com/reports/3443563 by somerandomdev

Summary:

The style sanitizer in Roundcube Webmail can be bypassed by creating HTML entities using CSS character escapes. This allows using arbitrary inline CSS, like e.g. url(), and retrieve the IP address and user agent of the person reading the email.

Identification Required

You must be logged in to read this writeup. Join our community of researchers today.

Related Writeups

Discussion

No comments yet. Be the first to share your thoughts.

Log in to join the discussion.

Sign In