CVE-2023-43770
MEDIUM KEVRoundcube <1.4.14, <1.5.4, <1.6.3 - XSS
Title source: llmDescription
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.
Exploits (3)
References (4)
Scores
CVSS v3
6.1
EPSS
0.8065
EPSS Percentile
99.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CISA KEV
2024-02-12
VulnCheck KEV
2024-02-12
InTheWild.io
2024-02-12
ENISA EUVD
EUVD-2023-48147
CWE
CWE-79
Status
published
Products (2)
debian/debian_linux
10.0
roundcube/webmail
< 1.4.14
Published
Sep 22, 2023
KEV Added
Feb 12, 2024
Tracked Since
Feb 18, 2026