Back to Changelog
Roundcube
v1.6.19
Security update fixing 12 vulnerabilities including stored XSS and SSRF filter bypass.
Bug Fix
1- Various regression fixes accumulated across the 1.6.16-1.6.19 patch releases.
Security Fixes
6- Fixed multiple zero-click stored XSS vulnerabilities in message rendering.
- Fixed SSRF protection bypass allowing requests to internal network resources.
- Fixed email header injection vulnerability.
- Fixed cross-user contact access vulnerability.
- Fixed XSS via crafted TNEF attachment content.
- Fixed SVG SMIL animation filter bypass allowing script execution.