Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-5631

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.907
EPSS Ranking 99.6%
CVSS Severity
CVSS v3 Score 6.1
Proposed Action
Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.
Ransomware Campaign
Unknown
References
Products affected by CVE-2023-5631


Contact Us

Shodan ® - All rights reserved