CVE-2012-6121
Roundcube Webmail < 0.8.4 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.8.5 allows remote attackers to inject arbitrary web script or HTML via a (1) data:text or (2) vbscript link.
References (7)
Scores
EPSS
0.0041
EPSS Percentile
60.8%
Details
CWE
CWE-79
Status
published
Products (39)
roundcube/webmail
< 0.8.4
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
roundcube/webmail
... and 29 more
Published
Feb 24, 2013
Tracked Since
Feb 18, 2026