CVE-2025-68460

Description

A flaw was found in Roundcube Webmail. This information disclosure vulnerability resides within the HTML style sanitizer, potentially allowing an attacker to gain unauthorized access to sensitive information. The vulnerability is triggered by improper handling of HTML styles.

Statement

This vulnerability is rated Low for Red Hat. The information disclosure flaw in Roundcube Webmail's HTML style sanitizer requires user interaction to exploit, limiting its impact in typical Red Hat deployments.

Understanding the Weakness (CWE)

Integrity

Technical Impact: Modify Application Data

The communications between components can be modified in unexpected ways. Unexpected commands can be executed, bypassing other security mechanisms. Incoming data can be misinterpreted.

Integrity,Confidentiality,Availability,Access Control

Technical Impact: Execute Unauthorized Code or Commands

The communications between components can be modified in unexpected ways. Unexpected commands can be executed, bypassing other security mechanisms. Incoming data can be misinterpreted.

Confidentiality

Technical Impact: Bypass Protection Mechanism

The communications between components can be modified in unexpected ways. Unexpected commands can be executed, bypassing other security mechanisms. Incoming data can be misinterpreted.

Frequently Asked Questions

Want to get errata notifications? Sign up here.