The Roundcube project reports:
- >Missing basic validation for content proxied by the css proxy
- SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets
- SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check
- remote content blocking bypass via unclosed url() in a FuncIRI attribute
- LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter
- arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions
- RCE via cmd_learn driver of markasjunk plugin
- Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization
- password’s modoboa driver leak of an authentication token to a user-controlled host
- stored XSS in “Add to address book” action
- HTML/CSS sanitization bypass via SVG animate by attribute