CVE-2015-8770 | RoundCube up to 1.0.7/1.1.3 rcmail_output_html.php set_skin path traversal (Advisory 135274 / EDB-39245)
A vulnerability was found in RoundCube up to 1.0.7/1.1.3 and classified as critical. Affected by this issue is the function set_skin of the file program/include/rcmail_output_html.php. The manipulation of the argument _skin leads to path traversal.
This vulnerability is handled as CVE-2015-8770. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.