Vulnerabilities
Vulnerable Software
Roundcube:  >> Webmail  >> 1.4.5  Security Vulnerabilities
Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.
CVSS Score
6.1
EPSS Score
0.007
Published
2020-08-12
An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists.
CVSS Score
6.1
EPSS Score
0.009
Published
2020-07-06


Contact Us

Shodan ® - All rights reserved