Record summary

CVE-2020-35730 has a selected CVSS score of 6.1 (medium); EIP currently links 1 repository PoC. CISA lists CVE-2020-35730 in KEV.

Description

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Jun 22, 2023 · CISA
VulnCheck KEV
Listed · Jun 20, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubskyllpro/CVE-2021-44026-PoCRepository PoCby skyllproStars: 0Not analyzed2 files

4.2 KiB · linked to 3 vulnerabilities

GitHub

PoC details

References

Showing 12 of 13