Looking for the vulnerability index of Invicti's legacy products?
Roundcube Improper Privilege Management Vulnerability (CVE-2017-8114) - Vulnerability Database

Roundcube Improper Privilege Management Vulnerability (CVE-2017-8114)

Description

Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.

References

Related Vulnerabilities