Potential Email Information Leak in Roundcube Webmail by Itself
CVE-2019-10740
4.3MEDIUM
What is CVE-2019-10740?
An issue exists in Roundcube Webmail prior to version 1.3.10 where an attacker can exploit encrypted emails using S/MIME or PGP. By embedding these encrypted parts within a specially crafted multipart email, attackers can disguise the malicious content using HTML/CSS or ASCII newline characters. When recipients reply to what appears to be a benign email, they unintentionally expose the plaintext of the encrypted messages to the attacker, thus leading to potential information disclosure.