Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2020-13964
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.009
EPSS Ranking
74.0%
CVSS Severity
CVSS v3 Score
6.1
CVSS v2 Score
4.3
References
https://github.com/roundcube/roundcubemail/commit/37e2bc745723ef6322f0f785aefd0b9313a40f19
https://github.com/roundcube/roundcubemail/releases/tag/1.3.12
https://github.com/roundcube/roundcubemail/releases/tag/1.4.5
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DLESQ4LPJGMSWHQ4TBRTVQRDG7IXAZCW/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ODPJXBHZ32QSP4MYT2OBCALYXSUJ47SK/
https://roundcube.net/news/2020/06/02/security-updates-1.4.5-and-1.3.12
https://www.debian.org/security/2020/dsa-4700
https://github.com/roundcube/roundcubemail/commit/37e2bc745723ef6322f0f785aefd0b9313a40f19
https://github.com/roundcube/roundcubemail/releases/tag/1.3.12
https://github.com/roundcube/roundcubemail/releases/tag/1.4.5
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DLESQ4LPJGMSWHQ4TBRTVQRDG7IXAZCW/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ODPJXBHZ32QSP4MYT2OBCALYXSUJ47SK/
https://roundcube.net/news/2020/06/02/security-updates-1.4.5-and-1.3.12
https://www.debian.org/security/2020/dsa-4700
Products affected by CVE-2020-13964
Roundcube
»
Webmail
»
Version:
N/A
cpe:2.3:a:roundcube:webmail:-
Roundcube
»
Webmail
»
Version:
0.1
cpe:2.3:a:roundcube:webmail:0.1
Roundcube
»
Webmail
»
Version:
0.1.1
cpe:2.3:a:roundcube:webmail:0.1.1
Roundcube
»
Webmail
»
Version:
0.2
cpe:2.3:a:roundcube:webmail:0.2
Roundcube
»
Webmail
»
Version:
0.2.1
cpe:2.3:a:roundcube:webmail:0.2.1
Roundcube
»
Webmail
»
Version:
0.2.2
cpe:2.3:a:roundcube:webmail:0.2.2
Roundcube
»
Webmail
»
Version:
0.3
cpe:2.3:a:roundcube:webmail:0.3
Roundcube
»
Webmail
»
Version:
0.3.1
cpe:2.3:a:roundcube:webmail:0.3.1
Roundcube
»
Webmail
»
Version:
0.4
cpe:2.3:a:roundcube:webmail:0.4
Roundcube
»
Webmail
»
Version:
0.4.1
cpe:2.3:a:roundcube:webmail:0.4.1
Roundcube
»
Webmail
»
Version:
0.4.2
cpe:2.3:a:roundcube:webmail:0.4.2
Roundcube
»
Webmail
»
Version:
0.5
cpe:2.3:a:roundcube:webmail:0.5
Roundcube
»
Webmail
»
Version:
0.5.1
cpe:2.3:a:roundcube:webmail:0.5.1
Roundcube
»
Webmail
»
Version:
0.5.2
cpe:2.3:a:roundcube:webmail:0.5.2
Roundcube
»
Webmail
»
Version:
0.5.3
cpe:2.3:a:roundcube:webmail:0.5.3
Roundcube
»
Webmail
»
Version:
0.5.4
cpe:2.3:a:roundcube:webmail:0.5.4
Roundcube
»
Webmail
»
Version:
0.6
cpe:2.3:a:roundcube:webmail:0.6
Roundcube
»
Webmail
»
Version:
0.7
cpe:2.3:a:roundcube:webmail:0.7
Roundcube
»
Webmail
»
Version:
0.7.1
cpe:2.3:a:roundcube:webmail:0.7.1
Roundcube
»
Webmail
»
Version:
0.7.2
cpe:2.3:a:roundcube:webmail:0.7.2
Roundcube
»
Webmail
»
Version:
0.7.3
cpe:2.3:a:roundcube:webmail:0.7.3
Roundcube
»
Webmail
»
Version:
0.7.4
cpe:2.3:a:roundcube:webmail:0.7.4
Roundcube
»
Webmail
»
Version:
0.8.0
cpe:2.3:a:roundcube:webmail:0.8.0
Roundcube
»
Webmail
»
Version:
0.8.1
cpe:2.3:a:roundcube:webmail:0.8.1
Roundcube
»
Webmail
»
Version:
0.8.2
cpe:2.3:a:roundcube:webmail:0.8.2
Roundcube
»
Webmail
»
Version:
0.8.3
cpe:2.3:a:roundcube:webmail:0.8.3
Roundcube
»
Webmail
»
Version:
0.8.4
cpe:2.3:a:roundcube:webmail:0.8.4
Roundcube
»
Webmail
»
Version:
0.8.5
cpe:2.3:a:roundcube:webmail:0.8.5
Roundcube
»
Webmail
»
Version:
0.8.6
cpe:2.3:a:roundcube:webmail:0.8.6
Roundcube
»
Webmail
»
Version:
0.8.7
cpe:2.3:a:roundcube:webmail:0.8.7
Roundcube
»
Webmail
»
Version:
0.9
cpe:2.3:a:roundcube:webmail:0.9
Roundcube
»
Webmail
»
Version:
0.9.0
cpe:2.3:a:roundcube:webmail:0.9.0
Roundcube
»
Webmail
»
Version:
0.9.1
cpe:2.3:a:roundcube:webmail:0.9.1
Roundcube
»
Webmail
»
Version:
0.9.2
cpe:2.3:a:roundcube:webmail:0.9.2
Roundcube
»
Webmail
»
Version:
0.9.3
cpe:2.3:a:roundcube:webmail:0.9.3
Roundcube
»
Webmail
»
Version:
0.9.4
cpe:2.3:a:roundcube:webmail:0.9.4
Roundcube
»
Webmail
»
Version:
0.9.5
cpe:2.3:a:roundcube:webmail:0.9.5
Roundcube
»
Webmail
»
Version:
1.0
cpe:2.3:a:roundcube:webmail:1.0
Roundcube
»
Webmail
»
Version:
1.0.0
cpe:2.3:a:roundcube:webmail:1.0.0
Roundcube
»
Webmail
»
Version:
1.0.1
cpe:2.3:a:roundcube:webmail:1.0.1
Roundcube
»
Webmail
»
Version:
1.0.10
cpe:2.3:a:roundcube:webmail:1.0.10
Roundcube
»
Webmail
»
Version:
1.0.11
cpe:2.3:a:roundcube:webmail:1.0.11
Roundcube
»
Webmail
»
Version:
1.0.12
cpe:2.3:a:roundcube:webmail:1.0.12
Roundcube
»
Webmail
»
Version:
1.0.2
cpe:2.3:a:roundcube:webmail:1.0.2
Roundcube
»
Webmail
»
Version:
1.0.3
cpe:2.3:a:roundcube:webmail:1.0.3
Roundcube
»
Webmail
»
Version:
1.0.4
cpe:2.3:a:roundcube:webmail:1.0.4
Roundcube
»
Webmail
»
Version:
1.0.5
cpe:2.3:a:roundcube:webmail:1.0.5
Roundcube
»
Webmail
»
Version:
1.0.6
cpe:2.3:a:roundcube:webmail:1.0.6
Roundcube
»
Webmail
»
Version:
1.0.7
cpe:2.3:a:roundcube:webmail:1.0.7
Roundcube
»
Webmail
»
Version:
1.0.8
cpe:2.3:a:roundcube:webmail:1.0.8
Roundcube
»
Webmail
»
Version:
1.0.9
cpe:2.3:a:roundcube:webmail:1.0.9
Roundcube
»
Webmail
»
Version:
1.1
cpe:2.3:a:roundcube:webmail:1.1
Roundcube
»
Webmail
»
Version:
1.1.0
cpe:2.3:a:roundcube:webmail:1.1.0
Roundcube
»
Webmail
»
Version:
1.1.1
cpe:2.3:a:roundcube:webmail:1.1.1
Roundcube
»
Webmail
»
Version:
1.1.10
cpe:2.3:a:roundcube:webmail:1.1.10
Roundcube
»
Webmail
»
Version:
1.1.11
cpe:2.3:a:roundcube:webmail:1.1.11
Roundcube
»
Webmail
»
Version:
1.1.12
cpe:2.3:a:roundcube:webmail:1.1.12
Roundcube
»
Webmail
»
Version:
1.1.2
cpe:2.3:a:roundcube:webmail:1.1.2
Roundcube
»
Webmail
»
Version:
1.1.3
cpe:2.3:a:roundcube:webmail:1.1.3
Roundcube
»
Webmail
»
Version:
1.1.4
cpe:2.3:a:roundcube:webmail:1.1.4
Roundcube
»
Webmail
»
Version:
1.1.5
cpe:2.3:a:roundcube:webmail:1.1.5
Roundcube
»
Webmail
»
Version:
1.1.6
cpe:2.3:a:roundcube:webmail:1.1.6
Roundcube
»
Webmail
»
Version:
1.1.7
cpe:2.3:a:roundcube:webmail:1.1.7
Roundcube
»
Webmail
»
Version:
1.1.8
cpe:2.3:a:roundcube:webmail:1.1.8
Roundcube
»
Webmail
»
Version:
1.1.9
cpe:2.3:a:roundcube:webmail:1.1.9
Roundcube
»
Webmail
»
Version:
1.2
cpe:2.3:a:roundcube:webmail:1.2
Roundcube
»
Webmail
»
Version:
1.2.0
cpe:2.3:a:roundcube:webmail:1.2.0
Roundcube
»
Webmail
»
Version:
1.2.1
cpe:2.3:a:roundcube:webmail:1.2.1
Roundcube
»
Webmail
»
Version:
1.2.10
cpe:2.3:a:roundcube:webmail:1.2.10
Roundcube
»
Webmail
»
Version:
1.2.11
cpe:2.3:a:roundcube:webmail:1.2.11
Roundcube
»
Webmail
»
Version:
1.2.12
cpe:2.3:a:roundcube:webmail:1.2.12
Roundcube
»
Webmail
»
Version:
1.2.13
cpe:2.3:a:roundcube:webmail:1.2.13
Roundcube
»
Webmail
»
Version:
1.2.2
cpe:2.3:a:roundcube:webmail:1.2.2
Roundcube
»
Webmail
»
Version:
1.2.3
cpe:2.3:a:roundcube:webmail:1.2.3
Roundcube
»
Webmail
»
Version:
1.2.4
cpe:2.3:a:roundcube:webmail:1.2.4
Roundcube
»
Webmail
»
Version:
1.2.5
cpe:2.3:a:roundcube:webmail:1.2.5
Roundcube
»
Webmail
»
Version:
1.2.6
cpe:2.3:a:roundcube:webmail:1.2.6
Roundcube
»
Webmail
»
Version:
1.2.7
cpe:2.3:a:roundcube:webmail:1.2.7
Roundcube
»
Webmail
»
Version:
1.2.8
cpe:2.3:a:roundcube:webmail:1.2.8
Roundcube
»
Webmail
»
Version:
1.2.9
cpe:2.3:a:roundcube:webmail:1.2.9
Roundcube
»
Webmail
»
Version:
1.3
cpe:2.3:a:roundcube:webmail:1.3
Roundcube
»
Webmail
»
Version:
1.3.0
cpe:2.3:a:roundcube:webmail:1.3.0
Roundcube
»
Webmail
»
Version:
1.3.1
cpe:2.3:a:roundcube:webmail:1.3.1
Roundcube
»
Webmail
»
Version:
1.3.10
cpe:2.3:a:roundcube:webmail:1.3.10
Roundcube
»
Webmail
»
Version:
1.3.11
cpe:2.3:a:roundcube:webmail:1.3.11
Roundcube
»
Webmail
»
Version:
1.3.2
cpe:2.3:a:roundcube:webmail:1.3.2
Roundcube
»
Webmail
»
Version:
1.3.3
cpe:2.3:a:roundcube:webmail:1.3.3
Roundcube
»
Webmail
»
Version:
1.3.4
cpe:2.3:a:roundcube:webmail:1.3.4
Roundcube
»
Webmail
»
Version:
1.3.5
cpe:2.3:a:roundcube:webmail:1.3.5
Roundcube
»
Webmail
»
Version:
1.3.6
cpe:2.3:a:roundcube:webmail:1.3.6
Roundcube
»
Webmail
»
Version:
1.3.7
cpe:2.3:a:roundcube:webmail:1.3.7
Roundcube
»
Webmail
»
Version:
1.3.8
cpe:2.3:a:roundcube:webmail:1.3.8
Roundcube
»
Webmail
»
Version:
1.3.9
cpe:2.3:a:roundcube:webmail:1.3.9
Roundcube
»
Webmail
»
Version:
1.4.0
cpe:2.3:a:roundcube:webmail:1.4.0
Roundcube
»
Webmail
»
Version:
1.4.1
cpe:2.3:a:roundcube:webmail:1.4.1
Roundcube
»
Webmail
»
Version:
1.4.2
cpe:2.3:a:roundcube:webmail:1.4.2
Roundcube
»
Webmail
»
Version:
1.4.3
cpe:2.3:a:roundcube:webmail:1.4.3
Roundcube
»
Webmail
»
Version:
1.4.4
cpe:2.3:a:roundcube:webmail:1.4.4
Debian
»
Debian Linux
»
Version:
10.0
cpe:2.3:o:debian:debian_linux:10.0
Debian
»
Debian Linux
»
Version:
9.0
cpe:2.3:o:debian:debian_linux:9.0
Fedoraproject
»
Fedora
»
Version:
31
cpe:2.3:o:fedoraproject:fedora:31
Fedoraproject
»
Fedora
»
Version:
32
cpe:2.3:o:fedoraproject:fedora:32
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved