A critical vulnerability in the widely-used Roundcube Webmail software is under active attack, prompting a sharp warning from cybersecurity authorities for administrators of self-hosted systems. According to reports, the issue is a pre-authentication SQL injection flaw that could allow an unauthenticated attacker to compromise a system.

The warning was issued by the Canadian Centre for Cyber Security and cited by The Hacker News. The report states the vulnerability exists within the virtuser_query plugin, affecting Roundcube versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1, with a cited CVSS score of 8.1. The technical root cause is described as a flaw in input processing related to a preg_replace() function call, which improperly sanitizes data.

Because the flaw is reported as exploitable without any credentials, it is considered exceptionally dangerous. Attackers can reportedly send crafted requests to the vulnerable parameter, potentially executing arbitrary SQL commands on the backend database. A successful attack could lead to full system takeover, data exfiltration, or persistent backdoor access.

Given the confirmed in-the-wild exploitation, administrators should act decisively. The following steps provide a clear remediation path:

Immediate Action Required: 1. Apply Official Patches: Upgrade to the patched versions without delay. For the 1.6.x branch, update to version 1.6.16. For the 1.7.x branch, update to version 1.7.1. 2. Deploy Interim Protections: If patching cannot be completed instantly, configure a Web Application Firewall (WAF) to block malicious requests targeting the virtuser_query parameter. 3. Evaluate Plugin Disabling: If the virtuser_query functionality is non-essential, consider disabling the plugin as a stopgap measure to eliminate the attack vector. 4. Audit for Compromise: Following mitigation, review system and database logs for any suspicious activity or indicators of compromise that may predate the patch.

Security experts agree that direct patching is the definitive solution. For organizations, particularly SMEs that often manage their own webmail infrastructure with limited resources, this incident highlights the essential need for rigorous patch management. The availability of official fixes places the responsibility squarely on administrators to assess and respond to the threat described in this report.


廣泛使用的 Roundcube 網頁郵件軟件中發現一個嚴重漏洞,正遭積極利用,網絡安全當局因此向自主託管系統的管理員發出嚴厲警告。據報導,該問題是一個預先驗證的 SQL injection 缺陷,可能允許未經驗證的攻擊者侵入系統。

警告由加拿大網絡安全中心發布,並由 The Hacker News 引用。報告指出,該漏洞存在於 virtuser_query 外掛中,影響 Roundcube 1.6.16 之前的 1.6.x 版本及 1.7.1 之前的 1.7.x 版本,CVSS 評分為 8.1。技術根源描述為與 preg_replace() 函數調用相關的輸入處理缺陷,導致數據未被妥善淨化。

由於據報導該漏洞無需任何憑證即可被利用,被視為極其危險。攻擊者可向易受攻擊的參數發送精心構造的請求,從而在後端數據庫上執行任意 SQL 指令。成功的攻擊可能導致系統完全被接管、數據被竊取或植入持久性後門。

鑑於已確認漏洞在野外遭積極利用,管理員應果斷採取行動。以下步驟提供了明確的補救路徑:

需立即採取的行動: 1. 套用官方修補程式:毫不拖延地升級至已修補的版本。對於 1.6.x 分支,更新至 1.6.16 版本。對於 1.7.x 分支,更新至 1.7.1 版本。 2. 部署臨時防護措施:若無法立即完成修補,請配置 Web 應用程式防火牆(WAF)以阻止針對 virtuser_query 參數的惡意請求。 3. 評估停用外掛:若 virtuser_query 功能非必要,可考慮將此外掛停用作為權宜之計,以消除攻擊向量。 4. 審計系統是否已被入侵:在採取緩解措施後,請檢查系統和數據庫日誌,尋找任何可疑活動或可能先於修補發生的入侵跡象。

安全專家一致認為,直接套用修補程式是最終解決方案。對組織而言,尤其是資源有限、通常自行管理網頁郵件基礎設施的中小企業,此事件突顯了嚴格執行修補程式管理的必要性。官方修補程式的及時發布將應對本報告所述威脅之責任完全交予管理員承擔。

新聞來源 / Original News Source