Описание
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support |
devel | not-affected | 1.6.6+dfsg-1 |
esm-apps/bionic | released | 1.3.6+dfsg.1-1ubuntu0.1~esm3 |
esm-apps/focal | released | 1.4.3+dfsg.1-1ubuntu0.1~esm3 |
esm-apps/jammy | released | 1.5.0+dfsg.1-2ubuntu0.1~esm2 |
esm-apps/noble | not-affected | 1.6.6+dfsg-1 |
esm-apps/xenial | released | 1.2~beta+dfsg.1-0ubuntu1+esm3 |
focal | ignored | end of standard support, was needed |
jammy | needed | |
lunar | ignored | end of life, was needs-triage |
Показывать по
Ссылки на источники
EPSS
6.1 Medium
CVSS3
Связанные уязвимости
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 al ...
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.
Уязвимость компонента program/lib/Roundcube/rcube_string_replacer.php почтового клиента RoundCube Webmail, позволяющая нарушителю провести атаку межсайтового скриптинга
EPSS
6.1 Medium
CVSS3