Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mh9g-rh94-w7mh

Опубликовано: 17 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.8

Описание

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.

EPSS

Процентиль: 23%
0.00307
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-669

Связанные уязвимости

CVSS3: 5.8
ubuntu
10 дней назад

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.

CVSS3: 5.8
nvd
10 дней назад

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.

CVSS3: 5.8
debian
10 дней назад

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed ...

EPSS

Процентиль: 23%
0.00307
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-669