github roundcube/roundcubemail 1.2.12
Roundcube Webmail 1.2.12

latest releases: 1.6.6, 1.4.16, 1.6.5...
3 years ago

This is a security update to the LTS version 1.2.
It fixes two recently reported cross-site scripting (XSS) vulnerabilities via HTML messages with malicious svg and math contents.

Credits for these findings go to Łukasz Pilorz from Pentesters.

We strongly recommend to update all productive installations of Roundcube 1.2.x if you cannot upgrade to a more recent version.
Please do backup your data before updating!

Don't miss a new roundcubemail release

NewReleases is sending notifications on new releases.