Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-68461

Опубликовано: 18 дек. 2025
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

Roundcube Webmail contains a Cross-Site Scripting (XSS) vulnerability in its SVG handling. The application fails to properly sanitize the tag within SVG documents, allowing attackers to inject malicious scripts, potentially enabling session hijacking, credential theft, or unauthorized actions on behalf of the victim.

Отчет

This flaw is rated Moderate because successful exploitation requires user interaction - the victim must open an email containing a malicious SVG attachment or view inline SVG content. While this limits the attack surface, a successful exploit could allow an attacker to execute scripts in the victim's webmail session, potentially leading to session hijacking or unauthorized actions.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2423507roundcubemail: Roundcube Webmail: Cross-Site Scripting (XSS) vulnerability via crafted SVG animate tag

EPSS

Процентиль: 91%
0.06437
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.2
ubuntu
4 месяца назад

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

CVSS3: 7.2
nvd
4 месяца назад

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

CVSS3: 7.2
debian
4 месяца назад

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cr ...

CVSS3: 7.2
github
4 месяца назад

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

CVSS3: 7.2
fstec
4 месяца назад

Уязвимость почтового клиента RoundCube Webmail, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю проводить межсайтовые сценарные атаки (XSS)

EPSS

Процентиль: 91%
0.06437
Низкий

6.1 Medium

CVSS3