Описание
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.
Ссылки
- Patch
- Patch
- Patch
- Release Notes
- Release Notes
- Release Notes
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.5.14 (исключая)Версия от 1.6.0 (включая) до 1.6.14 (исключая)
Одно из
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
EPSS
Процентиль: 17%
0.00251
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
ubuntu
4 месяца назад
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.
CVSS3: 6.1
debian
4 месяца назад
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. ...
CVSS3: 6.1
github
4 месяца назад
Roundcube Webmail: Insufficient HTML attachment sanitization in preview mode
CVSS3: 6.1
fstec
5 месяцев назад
Уязвимость режима предварительного просмотра почтового клиента RoundCube Webmail, позволяющая нарушителю проводить межсайтовые сценарные атаки (XSS)
EPSS
Процентиль: 17%
0.00251
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79