Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-42009 PoC — Roundcube Webmail 安全漏洞

Source
Associated Vulnerability
Title: Roundcube Webmail 安全漏洞 (CVE-2024-42009)
Description:A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
Description
This script exploits a stored XSS vulnerability (CVE-2024-42009) in Roundcube Webmail version 1.6.7. It injects a malicious payload into the webmail system, which, when triggered, exfiltrates email content from the victim’s inbox.
Readme
# XSS Exploit for Roundcube Webmail 1.6.7 (CVE-2024-42009)

## Description
This script exploits a stored XSS vulnerability (CVE-2024-42009) in Roundcube Webmail version 1.6.7. It injects a malicious payload into the webmail system, which, when triggered, exfiltrates email content from the victim’s inbox.

## Features
- Uses a Python HTTP listener to capture and decode stolen email content.
- Sends an XSS payload via a contact form.
- Extracts and prints the captured email body.

## Usage
1. **Start the listener:**
   ```bash
   python3 exploit.py
   ```
2. **Configure your attack settings in `exploit.py`**
   - Set `TARGET_URL` to the target Roundcube instance.
   - Replace `YOUR_IP:4444` with your actual listener IP and port.
3. **Monitor captured email content in real time.**

## Reference
A good reference for understanding the impact of this vulnerability can be found in this blog post:  
[Government Emails at Risk: Critical Cross-Site Scripting Vulnerability in Roundcube Webmail](https://www.sonarsource.com/blog/government-emails-at-risk-critical-cross-site-scripting-vulnerability-in-roundcube-webmail/)

## Disclaimer
This exploit is for educational and authorized penetration testing purposes only. Unauthorized use against systems you do not own or have explicit permission to test is illegal. I am not the person who discovered CVE-2024-42009. This exploit was created using information from various blogs with small help from DeepSeek.

## Requirements
- Python 3.x
- `requests`, `beautifulsoup4` libraries (install with `pip install requests beautifulsoup4`)

## License
This project is for educational use only. Use it responsibly.
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →