{"id":"CVE-2011-1491","details":"The login form in Roundcube Webmail before 0.5.1 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then compose an e-mail message, related to a \"login CSRF\" issue.","modified":"2026-04-10T03:41:44.392395Z","published":"2011-04-08T15:17:28Z","references":[{"type":"FIX","url":"http://openwall.com/lists/oss-security/2011/03/24/4"},{"type":"FIX","url":"http://openwall.com/lists/oss-security/2011/04/04/50"},{"type":"FIX","url":"http://trac.roundcube.net/changeset/4490"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2011/03/24/3"},{"type":"WEB","url":"http://trac.roundcube.net/wiki/Changelog"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66815"}],"schema_version":"1.7.5"}