CVE-2016-9920 | RoundCube Webmail up to 1.1.6/1.2.2 Sendmail steps/mail/sendmail.inc From access control (Nessus ID 96124 / ID 276345)
A vulnerability classified as critical has been found in RoundCube Webmail up to 1.1.6/1.2.2. This affects an unknown part of the file steps/mail/sendmail.inc of the component Sendmail. The manipulation of the argument From leads to improper access controls.
This vulnerability is uniquely identified as CVE-2016-9920. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.