CVE-2023-3221

Publication date

2023-09-04 12:31:30

Family

INCIBE

State

PUBLISHED

Description

User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the database.