Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2m7q-4j9m-89vh

Опубликовано: 26 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.4

Описание

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.

EPSS

Процентиль: 15%
0.00239
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.4
ubuntu
2 месяца назад

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.

CVSS3: 4.4
nvd
2 месяца назад

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.

CVSS3: 4.4
debian
2 месяца назад

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an un ...

CVSS3: 4.4
fstec
2 месяца назад

Уязвимость почтового клиента RoundCube Webmail, связанная с непринятия мер по защите структуры веб-страницы, позволяющая нарушителю проводить межсайтовые сценарные атаки (XSS)

suse-cvrf
2 месяца назад

Security update for roundcubemail

EPSS

Процентиль: 15%
0.00239
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-79