CVE-2020-13965
MEDIUM KEVRoundcube Webmail < 1.3.12 - Basic XSS
Title source: ruleDescription
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
Exploits (1)
References (10)
Scores
CVSS v3
6.1
EPSS
0.7182
EPSS Percentile
98.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CISA KEV
2024-06-26
VulnCheck KEV
2024-06-26
InTheWild.io
2024-06-26
ENISA EUVD
EUVD-2020-6139
CWE
CWE-80
CWE-79
Status
published
Products (5)
debian/debian_linux
9.0
debian/debian_linux
10.0
fedoraproject/fedora
31
fedoraproject/fedora
32
roundcube/webmail
< 1.3.12
Published
Jun 09, 2020
KEV Added
Jun 26, 2024
Tracked Since
Feb 18, 2026