
Hacking
Roundcube CVE-2024-42008 and CVE-2024-42010 PoC
A proof of concept demonstrating the exploitation of two vulnerabilities in Roundcube Webmail, CVE-2024-42008 and CVE-2024-42010, allowing for unauthorized access and potential remote code execution.
Check out this new PoC released by Viktor Markopoulos for Roundcube Webmail (CVE-2024-42008 & CVE-2024-42010).
I had a great time collaborating on the CSS exfiltration logic for this chain. We used a side-channel attack to leak attachment UIDs, which is then used to trigger the XSS.
Full article here: https://vict0ni.notion.site/roundcube-cve-2024-42008-and-cve-2024-42010-poc