Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-15562

An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 73.8%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
References
Products affected by CVE-2020-15562


Contact Us

Shodan ® - All rights reserved