CVE-2012-6121

Roundcube Webmail < 0.8.4 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.8.5 allows remote attackers to inject arbitrary web script or HTML via a (1) data:text or (2) vbscript link.

Scores

EPSS 0.0041
EPSS Percentile 60.8%

Details

CWE
CWE-79
Status published
Products (39)
roundcube/webmail < 0.8.4
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
... and 29 more
Published Feb 24, 2013
Tracked Since Feb 18, 2026