Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92r9-jpwj-c2mw

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.

program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.

EPSS

Процентиль: 68%
0.00585
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
около 11 лет назад

program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.

nvd
около 11 лет назад

program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.

debian
около 11 лет назад

program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does ...

EPSS

Процентиль: 68%
0.00585
Низкий

Дефекты

CWE-79