Description
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
Remediation
References
Related Vulnerabilities
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0185)
Ruby on Rails Improper Access Control Vulnerability (CVE-2015-7577)
WordPress Plugin LIQUID SPEECH BALLOON Cross-Site Scripting (1.0.6)
Apache Traffic Server Deserialization of Untrusted Data Vulnerability (CVE-2026-58163)
MediaWiki Improper Access Control Vulnerability (CVE-2012-4380)