CVE-2023-43770

MEDIUM KEV

Roundcube <1.4.14, <1.5.4, <1.6.3 - XSS

Title source: llm

Description

Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.

Exploits (3)

nomisec WORKING POC 33 stars
by s3cb0y · client-side
https://github.com/s3cb0y/CVE-2023-43770-POC
nomisec WRITEUP 3 stars
by knight0x07 · poc
https://github.com/knight0x07/CVE-2023-43770-PoC
nomisec WORKING POC
by skyllpro · client-side
https://github.com/skyllpro/CVE-2021-44026-PoC

Scores

CVSS v3 6.1
EPSS 0.8065
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CISA KEV 2024-02-12
VulnCheck KEV 2024-02-12
InTheWild.io 2024-02-12
ENISA EUVD EUVD-2023-48147
CWE
CWE-79
Status published
Products (2)
debian/debian_linux 10.0
roundcube/webmail < 1.4.14
Published Sep 22, 2023
KEV Added Feb 12, 2024
Tracked Since Feb 18, 2026