Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-37383

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.739
EPSS Ranking 98.7%
CVSS Severity
CVSS v3 Score 6.1
Proposed Action
RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code.
Ransomware Campaign
Unknown
Products affected by CVE-2024-37383


Contact Us

Shodan ® - All rights reserved