Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4649-47v5-9mqg

Опубликовано: 17 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.8

Описание

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.

EPSS

Процентиль: 25%
0.00322
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-669

Связанные уязвимости

CVSS3: 5.8
ubuntu
10 дней назад

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.

CVSS3: 5.8
nvd
10 дней назад

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.

CVSS3: 5.8
debian
10 дней назад

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HT ...

EPSS

Процентиль: 25%
0.00322
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-669