bugs.debian.orgConfirmation
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=978491 CVE-2020-35730
MEDIUMCISA KEV
Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
Record summary
CVE-2020-35730 has a selected CVSS score of 6.1 (medium); EIP currently links 1 repository PoC. CISA lists CVE-2020-35730 in KEV.
Description
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Jun 22, 2023 · CISA
- VulnCheck KEV
- Listed · Jun 20, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Roundcube WebmailBrowse Roundcube / Roundcube Webmail | CISA | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubskyllpro/CVE-2021-44026-PoCRepository PoCby skyllproStars: 0Not analyzed2 files
References
Showing 12 of 13github.comConfirmation
https://github.com/roundcube/roundcubemail/compare/1.4.9...1.4.10 github.comConfirmation
https://github.com/roundcube/roundcubemail/releases/tag/1.2.13 github.comConfirmation
https://github.com/roundcube/roundcubemail/releases/tag/1.3.16 github.comConfirmation
https://github.com/roundcube/roundcubemail/releases/tag/1.4.10 FEDORA-2021-73359af51cVendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCEU4BM5WGIDJWP6Z4PCH62ZMH57QYM2 FEDORA-2021-2cb0643316Vendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HMLIZWKMTRCLU7KZLEQHELS4INXJ7X5Q lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HCEU4BM5WGIDJWP6Z4PCH62ZMH57QYM2 lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HMLIZWKMTRCLU7KZLEQHELS4INXJ7X5Q nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-35730 roundcube.net
https://roundcube.net/download alexbirnberg.com
https://www.alexbirnberg.com/roundcube-xss.html