Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-44qp-5pm8-6j8p

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.

EPSS

Процентиль: 99%
0.82687
Высокий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-80

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 5 лет назад

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.

CVSS3: 6.1
redhat
больше 5 лет назад

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.

CVSS3: 6.1
nvd
больше 5 лет назад

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.

CVSS3: 6.1
debian
больше 5 лет назад

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x b ...

CVSS3: 4.7
fstec
больше 5 лет назад

Уязвимость почтового клиента RoundCube Webmail, связанная с недостатками используемых мер по защите структур веб-страницы, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 99%
0.82687
Высокий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-80