When a victim views a malicious email in Roundcube sent by an attacker, the attacker can execute arbitrary JavaScript in the victim's browser.
Attackers can gain a persistent foothold in the victim's browser, allowing them to continuously exfiltrate emails or steal the victim's password without additional user interaction.
Collection
[
|
...
]