Описание
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
Ссылки
- ExploitThird Party Advisory
- PatchThird Party Advisory
- Patch
- Release Notes
- Release Notes
- Mailing List
- Mailing List
- Vendor Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- Patch
- Release Notes
- Release Notes
- Mailing List
- Mailing List
- Vendor Advisory
- Third Party Advisory
- US Government Resource
Уязвимые конфигурации
Одно из
Одно из
Одно из
EPSS
6.1 Medium
CVSS3
6.3 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x b ...
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
Уязвимость почтового клиента RoundCube Webmail, связанная с недостатками используемых мер по защите структур веб-страницы, позволяющая нарушителю оказать воздействие на целостность данных
EPSS
6.1 Medium
CVSS3
6.3 Medium
CVSS3
4.3 Medium
CVSS2