kravietz 🦇 on Nostr: #RoundCube #webmail admins brace for CVE-2025-68461, remote (!) mailbox takeover ...
#RoundCube #webmail admins brace for CVE-2025-68461, remote (!) mailbox takeover exploited by a single email sent to the victim using #XSS
#infosec
Published at
2025-12-20 10:33:55 UTCEvent JSON
{
"id": "80b6838964c56aef069e7f145f6d9adf3e4dfb28b13129ec39675c19db519eb5",
"pubkey": "0f46532a2b56f6974d240758fd018297fdf9ac640bb0af96162890773e9e2196",
"created_at": 1766226835,
"kind": 1,
"tags": [
[
"t",
"xss"
],
[
"t",
"roundcube"
],
[
"t",
"webmail"
],
[
"t",
"infosec"
],
[
"proxy",
"https://agora.echelon.pl/objects/44d29545-8f4d-43ec-8b7b-a5a9706aa390",
"activitypub"
],
[
"L",
"pink.momostr"
],
[
"l",
"pink.momostr.activitypub:https://agora.echelon.pl/objects/44d29545-8f4d-43ec-8b7b-a5a9706aa390",
"pink.momostr"
],
[
"-"
]
],
"content": "#RoundCube #webmail admins brace for CVE-2025-68461, remote (!) mailbox takeover exploited by a single email sent to the victim using #XSS\r\n\r\n#infosec",
"sig": "bb0b09982ec49123c7fdfd12a7f31d260e7f7380ce9b7f36a1410b973dab4c981474d115305ba5211b0550e3330673d131e8529d7fde5388e5ef3d20c0f90831"
}