Description
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
Remediation
References
Related Vulnerabilities
PHP Use of Password Hash With Insufficient Computational Effort Vulnerability (CVE-2023-0567)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-0790)
WordPress 4.8.x Multiple Vulnerabilities (4.8 - 4.8.9)
WordPress Plugin Ginger-EU Cookie Law Multiple Vulnerabilities (4.1.3)