Описание
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.
Ссылки
- Patch
- Patch
- Release Notes
- Release Notes
- Vendor Advisory
Уязвимые конфигурации
EPSS
5.4 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
Связанные уязвимости
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insu ...
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages
Уязвимость почтового клиента RoundCube Webmail, связанная с отсутствием проверки корректности принимаемых запросов, позволяющая нарушителю раскрыть защищаемую информацию
EPSS
5.4 Medium
CVSS3
6.5 Medium
CVSS3