Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
2019-08-20T01:15:09.977
2024-11-21T04:28:15.890
Modified
CVSSv3.1: 7.4 (HIGH)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | roundcube | webmail | ≤ 1.3.9 | Yes |
Operating System | fedoraproject | fedora | 29 | Yes |