Description
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
Remediation
References
Related Vulnerabilities
Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2021-33327)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-31546)
Oracle Database Server Other Vulnerability (CVE-2002-0843)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-1590)
WordPress Plugin GD Rating System Multiple Vulnerabilities (2.3)