# L35-add — jQuery 3.2.1 Analysis + Real Roundcube 1.3.x Attack Surface
# Date: 2026-09-02

## jQuery 3.2.1 — CLIENT-SIDE ONLY (not exploitable server-side)

| CVE | Type | Impact on Roundcube |
|-----|------|---------------------|
| CVE-2019-11358 | Prototype Pollution | LOW — affects JS in browser, not server |
| CVE-2020-11023 | DOM XSS | LOW — requires crafted HTML in page |

**Verdict**: jQuery vulns are **browser-side only**. Cannot be used to compromise the server. They could be used to attack *users* of Roundcube (XSS in email), but that's a different attack vector.

## REAL Roundcube 1.3.x Attack Surface (from CVE research)

### CRITICAL (server-side)
| CVE | Version | Type | Auth | Status |
|-----|---------|------|------|--------|
| CVE-2025-49113 | <1.6.5 | PHP Object Injection → RCE | Post-auth | NOT TESTED (need creds) |
| CVE-2020-12641 | <1.4.4 | RCE via attachment | Post-auth | NOT TESTED |
| CVE-2017-16652 | <1.2.3 | File disclosure | Unauth | **NOT VULNERABLE** (nginx blocks) |

### HIGH (user-side / email-based)
| CVE | Version | Type | Auth |
|-----|---------|------|------|
| CVE-2024-37383 | <1.5.7 | Stored XSS (SVG) | Send email |
| CVE-2023-47272 | <1.6.4 | XSS (linkref) | Send email |
| CVE-2018-1000073 | <1.2.10 | XSS (mail preview) | Send email |
| CVE-2018-1000074 | <1.2.10 | CSRF token bypass | User clicks |

### MEDIUM (info disclosure)
| CVE | Version | Type |
|-----|---------|------|
| Source code exposure | 1.3.x | program/steps/*.inc readable |

## ATTACK SCENARIOS

### Scenario A: Unauthenticated (hardest)
- File disclosure: BLOCKED by nginx
- Source code: PARTIAL (can read some .inc files)
- **Result**: No unauth RCE possible

### Scenario B: With credentials (easiest)
1. Get any valid Roundcube login (from kedebah/hellio password reuse)
2. Login to Roundcube
3. CVE-2025-49113: Upload malicious image with PHP object payload
4. RCE as www-data

### Scenario C: Phishing (user interaction)
1. Send malicious email to any Npontu employee
2. CVE-2024-37383: Stored XSS in email
3. Steal session cookie
4. Use session to access Roundcube

## RECOMMENDATION

**Roundcube is NOT a viable unauthenticated target.**

Options:
1. **Password reuse** (fastest): Try known Npontu passwords on Roundcube login
2. **Phishing** (slow): Send XSS email to employees
3. **Skip Roundcube** (recommended): Focus on already-compromised vectors (GitLab, DBs, host A)

## FILES
- L35_roundcube_assessment.md (original)
- L36_password_reuse_analysis.md (password candidates)
