CVE-2024-42009
KEVCRITICAL 9.3EPSS 82.9%
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
- CVSS v3.1
- 9.3 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N - CVSS v3.1
- 9.3 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N - EPSS
- 82.88% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2025-06-09
- Nuclei
- critical · CWE-79
- Published
- 2024-08-05
- Updated
- 2025-10-21
Proof-of-concept exploits (7)
- 0xbassiouny1337/CVE-2024-420094★ · 2025-02-12
- Bhanunamikaze/CVE-2024-420091★ · 2025-03-03
- DaniTheHack3r/CVE-2024-42009-PoC8★ · 2025-05-30
- Foxer131/CVE-2024-42008-9-exploit0★ · 2025-05-26
- Shubhankargupta691/CVE-2024-420090★ · 2025-09-17
- ZaidArif47/CVE-2024-42009
- segunakinsoyinu/CVE-2024-42009-roundcube-xss