Showing 1 vulnerability on this page for Roundcubemail

Signals CISA KEV Ransomware Nuclei
Roundcube vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Stored XSS vulnerability in Roundcube

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.

CWE-79Oct 18, 2023
CVSS6.1v3.1EPSS75.9%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX