3 ms·
Here's an old XSS exploit for Roundcube from 2013: https://www.intelligentexploit.com/view-details.html?id=16961 https://www.intelligentexploit.com/view-detail
by xrorre 10y ago
Here's an old XSS exploit for Roundcube from 2013:
https://www.intelligentexploit.com/view-details.html?id=16961 https://www.intelligentexploit.com/view-details.html?id=1696...
I still use RC despite the long history of XSS attacks against it. Luckily RC uses progressive enhancement, so it still works with JS turned off. I just assume emails can still execute JS in 2016? Perhaps it's wrong of me to use RC with JS turned off as a preventative measure, but you have to adore that user interface! It's the only reason I choose RC over other self-hosted email web apps (and there are few to choose from in this space). I like the simplicity of Squirrel-mail, but Roundcube looks and feels too good not to use.
- ryanlol 10y agoWhat about the various RCE bugs, do those not worry you?
- dguido 10y agoYou're right. Before any integration of a server-side PGP key like this, they ought to have deployed some basic hygiene like a strict Content Security Policy (CSP) and a better sanitization library like HTMLpurifier. I don't trust webmail software, and definitely not PHP webmail software, to hold my keys for me otherwise.