CVE-2020-13965
MEDIUM KEVRoundcube Webmail < 1.3.12 and 1.4.x < 1.4.5 - Stored Cross-Site Scripting via XML Attachment Preview
Title source: llmExploitation Summary
CVE-2020-13965 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 26, 2024. EIP tracks 1 public exploit from researchers including mbadanoiu.
AI-analyzed exploit summary This repository contains a writeup for CVE-2020-13965, an XSS vulnerability in Roundcube Webmail. The vulnerability allows arbitrary JavaScript execution via a malicious XML attachment, bypassing the script filter when previewed or clicked.
Description
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
Exploits (1)
This repository contains a writeup for CVE-2020-13965, an XSS vulnerability in Roundcube Webmail. The vulnerability allows arbitrary JavaScript execution via a malicious XML attachment, bypassing the script filter when previewed or clicked.
References (10)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N