CVE-2024-42009

Published Aug 5, 2024

Last updated 8 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-42009 is a Cross-Site Scripting (XSS) vulnerability affecting Roundcube webmail software, specifically versions 1.5.7 and 1.6.x up to 1.6.7. It stems from a flaw in the `message_body()` function within the `program/actions/mail/show.php` file, where a desanitization issue can be exploited. This vulnerability allows a remote attacker to steal and send emails of a victim by sending a specially crafted email message. When a user views this malicious email in Roundcube, the attacker can execute arbitrary JavaScript in the victim's browser, potentially gaining persistent access to exfiltrate emails or steal passwords.

Description
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
Source
cve@mitre.org
NVD status
Analyzed
Products
webmail

Risk scores

CVSS 3.1

Type
Primary
Base score
9.3
Impact score
5.8
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
RoundCube Webmail Cross-Site Scripting Vulnerability
Exploit added on
Jun 9, 2025
Exploit action due
Jun 30, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
CWE-79
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-79

Social media

Hype score
Not currently trending
  1. #CyberAlert | Update: Roundcube Webmail vulnerabilities CVE-2024-42009 and CVE-2025-49113 https://t.co/fjBGTsQrMa https://t.co/fyi0kpLXFO

    @cybercentre_ca

    10 Jul 2026

    486 Impressions

    1 Retweet

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. #CyberAlerte | Vulnérabilités de Roundcube Webmail CVE-2024-42009 et CVE-2025-49113 https://t.co/IZRF4UjOSw https://t.co/dk1r5jLKjx

    @centrecyber_ca

    10 Jul 2026

    93 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Proofpoint: China-aligned UNK_MassTraction exploiting RoundCube mailservers belonging to the physics and engineering departments of US and Canadian universities with CVE-2024-42009 since May 2026. https://t.co/MdfGHB5xni

    @CTITraffic

    9 Jul 2026

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. a china-aligned crew (UNK_MassTraction) is quietly exploiting two roundcube webmail bugs, CVE-2024-42009 and CVE-2025-49113, to get into US and canadian university mail servers. the targeting is the tell: physics and engineering departments, the research inboxes. this is

    @PurpleOps_io

    9 Jul 2026

    132 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. Suspected China-aligned cluster targets US and Canadian universities via #Roundcube exploit chain: CVE-2024-42009 (CVSS 9.3) triggered by viewing a crafted email, chained with CVE-2025-49113 (CVSS 9.9) deserialization for RCE. Focus on research-value departments. https://t.co/VpI

    @MeridianEU

    9 Jul 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. TRC analysis shows China-linked threat actors chained CVE-2024-42009 and CVE-2025-49113 to compromise Roundcube webmail servers at academic institutions. Attackers deployed IceCube stealer and SquareShell webshell, then moved laterally to exfiltrate research data. Runtime

    @aviatrixtrc

    9 Jul 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2024-42009: Is Roundcube's Flaw an Urgent Breach or Policy Oversight? https://t.co/IlshIm3w2Y #CVE202442009 #Roundcube #CyberSecurity

    @cyber_newsroom

    8 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2024-42009: Academic Espionage Campaign Lacks Solid Evidence https://t.co/UDGFXZGy1t #CVE2024 #CyberSecurity #Espionage

    @cyber_newsroom

    8 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Roundcube Flaw CVE-2024-42009: Academic Espionage Raises Governance Concerns https://t.co/Q0OlTInPJU #CyberSecurity #DataPrivacy #AcademicEspionage

    @cyber_newsroom

    8 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CVE-2024-42009: Roundcube Flaw Fuels Espionage Against Academic Research https://t.co/FdqzH9MpsR #CVE2024 #Roundcube #Cybersecurity

    @cyber_newsroom

    8 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CVE-2024-42009: Roundcube Exploit Shows How Academia Remains Targeted https://t.co/SqN4TR3NaE #CyberSecurity #Roundcube #CVE2024

    @cyber_newsroom

    8 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Chinese-linked UNK_MassTraction exploits CVE-2024-42009 (Roundcube XSS) to deploy IceCube stealer, then chains CVE-2025-49113 to drop SquareShell or VShell backdoor on university mail servers. Patch Roundcube now. #DFIR_Radar https://t.co/k0os84I0Dq

    @DFIR_Radar

    8 Jul 2026

    175 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  13. UNK_MassTraction Targets Universities with CVE-2024-42009 Exploits — A Policy Failure https://t.co/1sEQ9QtTB1 #CVE2024 #CyberSecurity #DataProtection

    @cyber_newsroom

    8 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 中国系と疑われる脅威主体がウェブメール製品Roundcubeの脆弱性を用いて米国とカナダの教育機関を攻撃している。Proofpoint社報告。活動をUNK_MassTractionと命名。侵害契機はクロスサイトスクリプティング脆弱性

    @__kokumoto

    8 Jul 2026

    725 Impressions

    0 Retweets

    7 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  15. 🔴 Çin bağlantılı siber sadırganlar, kritik Roundcube güvenlik açıklarını kullanarak ABD ve Kanada'daki üniversiteleri hedef aldı! Zincirleme saldırıda CVE-2024-42009 ve CVE-2025-49113 istismar edilerek yalnızca e-postanın görüntülenmesiyle başlayan süreç

    @ridvanyagli

    8 Jul 2026

    979 Impressions

    2 Retweets

    7 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  16. Chinese-aligned UNK_MassTraction targeted US 🇺🇸 and Canadian 🇨🇦 university physics and engineering departments via CVE-2024-42009 (Roundcube XSS). #DFIR_Radar https://t.co/wzolgsz9eJ

    @DFIR_Radar

    8 Jul 2026

    137 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  17. Chinese 🇨🇳 UNK_MassTraction chained CVE-2024-42009 and CVE-2025-49113 in Roundcube to compromise university mail servers, dropping VShell backdoors and webshells. Opening a single email triggers the exploit, no user interaction beyond that. #DFIR_Radar https://t.co/gbOySIo

    @DFIR_Radar

    7 Jul 2026

    168 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  18. Suspected China-aligned group UNK_MassTraction exploited CVE-2024-42009 and CVE-2025-49113 in Roundcube to breach physics and engineering departments at fewer than 10 U.S. and Canadian universities, Proofpoint reported. https://t.co/SszBIfmduc

    @threatcluster

    7 Jul 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  19. China-aligned threat actors exploited CVE-2024-42009 in Roundcube webmail to steal credentials from university staff via malicious JavaScript. Attackers then moved laterally across campus networks to exfiltrate sensitive research data. Runtime segmentation could help contain such

    @aviatrixtrc

    7 Jul 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Universities' Roundcube webmail hacked via CVE-2024-42009 flaw, what's your email security plan? Check your email for vulnerabilities with a free scan at https://t.co/mPfUgk5M8n, can you afford to wait? #emailsecurity #universityhacks #cyberthreats

    @Soemailsecurity

    7 Jul 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  21. Recent activity labelled 'UNK_MassTraction' is a cross scripting malware that exploits CVE-2024-42009, which affects RoundCube, has been attributed to Chinese actors. RoundCube itself is an IMAP email client used by educational institutions. The exploit has targeted both Canadian

    @Leila97726926

    7 Jul 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  22. TRC analysis shows UNK_MassTraction exploiting chained Roundcube vulnerabilities to compromise university mail servers. Attackers deployed webshells via CVE-2024-42009 and CVE-2025-49113, then moved laterally to exfiltrate physics and engineering research data. Runtime

    @aviatrixtrc

    7 Jul 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 🔍 How dangerous is Roundcube CVE-2024-42009? Attackers run malicious JavaScript in the victim's browser to silently steal inbox data, contacts & session tokens with zero logs. 😱 See the attack chain 👇 https://t.co/UGsG2dXaZF #AppSec #TechNews #cyberupdates365

    @secureblognews

    7 Jul 2026

    51 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 🚨 Chinese hackers are actively exploiting Roundcube Webmail (CVE-2024-42009)! 🛑 A stored XSS flaw lets APTs steal your emails & session cookies just by viewing a message. Full patch & IOC guide 👇 https://t.co/Z5MkGis5Yc #CyberSecurity #InfoSec #latestnews #USA

    @CyberUpdates365

    7 Jul 2026

    50 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 🚨 A suspected China-aligned threat cluster, tracked by Proofpoint as UNK_MassTraction, is exploiting Roundcube webmail flaws (CVE-2024-42009 and CVE-2025-49113) against physics and engineering departments at U.S. and Canadian universities; merely opening a malicious email

    @techepages

    7 Jul 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. Multiples vulnérabilités dans Roundcube (09 août 2024) — Le 4 août 2024, Roundcube a publié des correctifs concernant les vulnérabilités critiques CVE-2024-42008 et CVE-2024-42009 affectant son serveur de courriel. Ces vulnérabilités permettent des injections de code i

    @RotateKeys

    31 Jan 2026

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. 🚨 CVE-2024-42009 - critical 🚨 Roundcube Webmail - Cross-Site Scripting > A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6... 👾 https://t.co/eUCbFtFlGV @pdnuclei #NucleiTemplates #cve

    @pdnuclei_bot

    15 Oct 2025

    110 Impressions

    0 Retweets

    0 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  28. CISA adds critical vulnerabilities CVE-2025-32433 & CVE-2024-42009 to KEV catalog—impacting Erlang/OTP SSH & Roundcube Webmail. Exploits could lead to remote commands & email theft. Federal agencies must patch promptly ⚠️ #Erlang #Firefox #US https://t.co/ZocOD9

    @TweetThreatNews

    10 Jun 2025

    76 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  29. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性カタログに、Erlang/OTPのCVE-2025-32433とRoundCubeのCVE-2024-42009が追加。対処期限は通常の6/30で、ランサムウェア悪用は不知。 また、For

    @__kokumoto

    9 Jun 2025

    1104 Impressions

    0 Retweets

    6 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  30. 🛡️ We added RoundCube Webmail and Erlang/OTP vulnerabilities CVE-2024-42009 & CVE-2025-32433 to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/

    @CISACyber

    9 Jun 2025

    7590 Impressions

    21 Retweets

    43 Likes

    4 Bookmarks

    1 Reply

    0 Quotes

  31. 🚨 Threat Campaign: Belarus-Linked UNC1151 Exploits Roundcube CVE-2024-42009 in Spear Phishing Campaign Targeting Polish Entities to Steal Credentials via Malicious Service Worker🚨 Summary: UNC1151 launched a spear phishing campaign targeting Polish entities, exploiting htt

    @CyberxtronTech

    9 Jun 2025

    77 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. CERT Polska warns of UNC1151 spear phishing targeting Polish organizations via Roundcube flaw (CVE-2024-42009). Malicious emails use obfuscated JavaScript & Service Workers to steal login data. Stay alert! ⚠️ #Poland #CyberEspionage #Webmail https://t.co/ygadg7szUK

    @TweetThreatNews

    9 Jun 2025

    76 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. CERT Polska warns of a critical Roundcube XSS flaw (CVE-2024-42009) exploited by UNC1151 in spear phishing, stealing credentials and compromising Polish organizations. #Roundcube #XSS #Phishing #Cybersecurity #UNC1151 https://t.co/8rkhyOpBxE

    @Daily_CyberSec

    9 Jun 2025

    194 Impressions

    0 Retweets

    4 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  34. 🚨 ¡Vulnerabilidad crítica en Roundcube (CVE-2024-42009)! Permite ejecución remota tras login. Afecta a versiones <1.5.10 y <1.6.11p. Ya protegimos a nuestros clientes. ¿Y tú? 🔗 https://t.co/XjbBVybMeW #okITup #Seguridad https://t.co/0YyVHzJokd

    @okITupSL

    6 Jun 2025

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. Roundcube Risks CVE-2025-49113 vul analysis https://t.co/kvX9t6ymid CVE-2024-42009 https://t.co/GPyhSCFihi https://t.co/quZm7j9sZr

    @blackorbird

    6 Jun 2025

    904 Impressions

    2 Retweets

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  36. 🔐 CERT Polska ostrzega: Zidentyfikowano kampanię wymierzoną w polskie podmioty, wykorzystującą podatność CVE-2024-42009 w Roundcube. Wystarczy otworzyć spreparowanego maila, by złośliwy kod JavaScript przejął dane logowania i zainstalował tzw. Service Workera –

    @CYFRA_GOV_PL

    6 Jun 2025

    1239 Impressions

    4 Retweets

    6 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  37. ⚠️ Critical Roundcube flaw (CVE-2024-42009) exploited in spearphishing attack by UNC1151! Polish entities targeted. Update to 1.6.11/1.5.10 NOW & monitor for suspicious activity. Full details & IOCs: 🚨 #Cybersecurity #Roundcube #Spearphishing https://t.co/45aoHYoe

    @fernandokarl

    6 Jun 2025

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. ⚠️A spearphishing campaign exploiting the CVE-2024-42009 vulnerability in Roundcube. ‼️The vulnerability enables attackers to execute malicious JavaScript code when an e-mail message is opened. 📌High probability attribution to UNC1151 group. ➡️ More: https://t.

    @CERT_Polska_en

    5 Jun 2025

    4203 Impressions

    17 Retweets

    45 Likes

    17 Bookmarks

    0 Replies

    2 Quotes

  39. Hice una pequeña prueba de concepto para explotar el CVE-2024-42009. Sencillamente dije "no hay PoC buenos de este CVE, voy a crear uno!" y así fue en una noche 😎 https://t.co/T4wJ8bfsaY

    @DaniTheHack3r

    24 May 2025

    2061 Impressions

    9 Retweets

    44 Likes

    7 Bookmarks

    2 Replies

    0 Quotes

  40. XSS Exploit for Roundcube Webmail 1.6.7 (CVE-2024-42009) The exploit injects a malicious payload, allowing email exfiltration upon execution. 🔗 Check it out: https://t.co/yDvJugNQf8

    @0xBassiouny1337

    12 Feb 2025

    80 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  41. XSS Exploit for Roundcube Webmail 1.6.7 (CVE-2024-42009) The exploit injects a malicious payload, allowing email exfiltration upon execution. 🔗 Check it out: https://t.co/yDvJugNQf8

    @0xBassiouny1337

    12 Feb 2025

    118 Impressions

    0 Retweets

    7 Likes

    1 Bookmark

    0 Replies

    0 Quotes

Configurations