Description
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.
Remediation
References
Related Vulnerabilities
Apache Tomcat CVE-2026-24733 Vulnerability (CVE-2026-24733)
WordPress Plugin MasterStudy LMS-for Online Courses and Education Local File Inclusion (3.3.0)
Oracle Database Server Improper Access Control Vulnerability (CVE-2025-61749)
WordPress Plugin Analytics Stats Counter Statistics PHP Object Injection (1.2.2.5)