CVE-2012-3507
Roundcube Webmail < 0.7.3 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in program/steps/mail/func.inc in RoundCube Webmail before 0.8.0, when using the Larry skin, allows remote attackers to inject arbitrary web script or HTML via the email message subject.
References (7)
Scores
EPSS
0.0041
EPSS Percentile
60.8%
Classification
CWE
CWE-79
Status
published
Affected Products (40)
roundcube/webmail
< 0.7.3
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
... and 25 more
Timeline
Published
Aug 25, 2012
Tracked Since
Feb 18, 2026