Описание
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support |
devel | not-affected | 1.6.6+dfsg-2 |
esm-apps/bionic | not-affected | code not present |
esm-apps/focal | released | 1.4.3+dfsg.1-1ubuntu0.1~esm4 |
esm-apps/jammy | released | 1.5.0+dfsg.1-2ubuntu0.1~esm3 |
esm-apps/noble | not-affected | 1.6.6+dfsg-2 |
esm-apps/xenial | not-affected | code not present |
focal | ignored | end of standard support, was needed |
jammy | needed | |
lunar | ignored | end of life, was needs-triage |
Показывать по
10
Ссылки на источники
EPSS
Процентиль: 61%
0.00425
Низкий
6.1 Medium
CVSS3
Связанные уязвимости
CVSS3: 6.1
nvd
больше 1 года назад
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
CVSS3: 6.1
debian
больше 1 года назад
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a C ...
CVSS3: 6.1
github
больше 1 года назад
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
EPSS
Процентиль: 61%
0.00425
Низкий
6.1 Medium
CVSS3