Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-68460

Опубликовано: 18 дек. 2025
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

A flaw was found in Roundcube Webmail. This information disclosure vulnerability resides within the HTML style sanitizer, potentially allowing an attacker to gain unauthorized access to sensitive information. The vulnerability is triggered by improper handling of HTML styles.

Отчет

This vulnerability is rated Low for Red Hat. The information disclosure flaw in Roundcube Webmail's HTML style sanitizer requires user interaction to exploit, limiting its impact in typical Red Hat deployments.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-116
https://bugzilla.redhat.com/show_bug.cgi?id=2423487roundcubemail: Roundcube Webmail: Information Disclosure via HTML Style Sanitizer

EPSS

Процентиль: 16%
0.00249
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.2
ubuntu
8 месяцев назад

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

CVSS3: 7.2
nvd
8 месяцев назад

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

CVSS3: 7.2
debian
8 месяцев назад

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a in ...

CVSS3: 7.2
github
8 месяцев назад

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

CVSS3: 7.2
fstec
8 месяцев назад

Уязвимость модуля проверки стилей HTML почтового клиента RoundCube Webmail, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 16%
0.00249
Низкий

5.4 Medium

CVSS3