FreeBSD : roundcube -- XSS vulnerability (4ae68e7c-dda4-11e0-a906-00215c6a37bb)
Medium Nessus Plugin ID 56168
SynopsisThe remote FreeBSD host is missing a security-related update.
DescriptionRoundCube development Team reports :
We just published a new release which fixes a recently reported XSS vulnerability as an update to the stable 0.5 branch. Please update your installations with this new version or patch them with the fix which is also published in the downloads section or our sourceforge.net page.
During one of pen-tests I found that _mbox parameter is not properly sanitized and reflected XSS attack is possible.
SolutionUpdate the affected package.