DSA-5531-1 roundcube – security update

Read Time:12 Second

It was discovered that roundcube, a skinnable AJAX based webmail
solution for IMAP servers, did not properly sanitize HTML
messages. This would allow an attacker to load arbitrary JavaScript
code.

https://security-tracker.debian.org/tracker/DSA-5531-1

Read More

CVE-2021-46898

Read Time:10 Second

views/switch.py in django-grappelli (aka Django Grappelli) before 2.15.2 attempts to prevent external redirection with startswith(“/”) but this does not consider a protocol-relative URL (e.g., //example.com) attack.

Read More

CVE-2021-46897

Read Time:8 Second

views.py in Wagtail CRX CodeRed Extensions (formerly CodeRed CMS or coderedcms) before 0.22.3 allows upward protected/..%2f..%2f path traversal when serving protected media.

Read More