Roundcube’s Zero-Click Webmail XSS, and How Fast It Reached cPanel
Roundcube, the webmail client that ships as the default webmail on a large share of the world’s shared-hosting accounts, has patched a flaw that lets a single email run code in a victim’s session with no click required. The upstream fix landed on July 5 in Roundcube 1.6.17 and 1.7.2. Nine days later, on July 14, cPanel folded it … Continue reading Roundcube’s Zero-Click Webmail XSS, and How Fast It Reached cPanel
Copy and paste this URL into your WordPress site to embed
Copy and paste this code into your site to embed