Description
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Cerber Security, Anti-spam & Malware Scan Cross-Site Scripting (9.1)
MediaWiki Uncontrolled Resource Consumption Vulnerability (CVE-2021-46149)
MySQL Improper Authentication Vulnerability (CVE-2012-2122)
WordPress Plugin UpdraftPlus WordPress Backup Multiple Vulnerabilities (1.16.58)
Moodle Improper Authentication Vulnerability (CVE-2018-1082)