Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-68461

Опубликовано: 18 дек. 2025
Источник: redhat
CVSS3: 6.1
EPSS Средний

Описание

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

Roundcube Webmail contains a Cross-Site Scripting (XSS) vulnerability in its SVG handling. The application fails to properly sanitize the tag within SVG documents, allowing attackers to inject malicious scripts, potentially enabling session hijacking, credential theft, or unauthorized actions on behalf of the victim.

Отчет

This flaw is rated Moderate because successful exploitation requires user interaction - the victim must open an email containing a malicious SVG attachment or view inline SVG content. While this limits the attack surface, a successful exploit could allow an attacker to execute scripts in the victim's webmail session, potentially leading to session hijacking or unauthorized actions.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2423507roundcubemail: Roundcube Webmail: Cross-Site Scripting (XSS) vulnerability via crafted SVG animate tag

EPSS

Процентиль: 97%
0.20094
Средний

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.2
ubuntu
8 месяцев назад

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

CVSS3: 7.2
nvd
8 месяцев назад

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

CVSS3: 7.2
debian
8 месяцев назад

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cr ...

CVSS3: 7.2
github
8 месяцев назад

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

CVSS3: 7.2
fstec
8 месяцев назад

Уязвимость почтового клиента RoundCube Webmail, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю проводить межсайтовые сценарные атаки (XSS)

EPSS

Процентиль: 97%
0.20094
Средний

6.1 Medium

CVSS3