Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhgj-jxxf-gxj9

Опубликовано: 28 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

Roundcube's HTML sanitization path for message rendering allows loopback, localhost, RFC1918, link-local, and ULA URLs even when remote content loading is disabled. A remote attacker can send an HTML email that causes the victim's browser to issue requests to local or private-network services simply by opening the message preview.

Roundcube's HTML sanitization path for message rendering allows loopback, localhost, RFC1918, link-local, and ULA URLs even when remote content loading is disabled. A remote attacker can send an HTML email that causes the victim's browser to issue requests to local or private-network services simply by opening the message preview.

4.7 Medium

CVSS3

Дефекты

CWE-184

Связанные уязвимости

nvd
2 месяца назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

4.7 Medium

CVSS3

Дефекты

CWE-184