CVE-2023-5631
MEDIUM KEVRoundcube Webmail < 1.4.15 - XSS
Title source: ruleDescription
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.
Exploits (1)
Scores
CVSS v3
6.1
EPSS
0.8443
EPSS Percentile
99.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CISA KEV
2023-10-26
VulnCheck KEV
2023-10-25
InTheWild.io
2023-10-26
ENISA EUVD
EUVD-2023-57924
CWE
CWE-79
Status
published
Products (5)
debian/debian_linux
10.0
debian/debian_linux
11.0
debian/debian_linux
12.0
fedoraproject/fedora
39
roundcube/webmail
< 1.4.15
Published
Oct 18, 2023
KEV Added
Oct 26, 2023
Tracked Since
Feb 18, 2026