RSSAmplifier

Blog

NULL CATHEDRAL

Where nothing is sacred.

nullcathedral.comRSS feed ↗4 posts

Latest posts

Roundcube round two: three more sanitizer bypasses

Three more bypasses in Roundcube's HTML sanitizer: SMIL animation attributes load remote resources, unquoted body backgrounds enable CSS injection, and position:fixed !important enables phishing overlays.

Perfex CRM <=3.4.0 allows unauthenticated RCE via insecure deserialization

Perfex CRM passed the autologin cookie into unserialize() without validation, giving unauthenticated attackers remote code execution.

Hello world

About this blog and the author behind it.

Roundcube Webmail <1.5.13 / <1.6.13 allows attackers to force remote image loads via SVG feImage

Roundcube's HTML sanitizer doesn't treat SVG feImage href as an image source. Attackers can bypass remote image blocking to track email opens. (CVE-2026-25916)