CVE-2020-13965
בינונית 6.1 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
מדדים
- CVSS 3.1
-
6.1 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 77% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-79, CWE-80
מוצרים מושפעים
roundcube: webmail; debian: debian linux; fedoraproject: fedora
קישורים
- https://roundcube.net/news/2020/06/02/security-updates-1.4.5-and-1.3.12 Vendor Advisory
- https://roundcube.net/news/2020/06/02/security-updates-1.4.5-and-1.3.12 Vendor Advisory
- https://github.com/roundcube/roundcubemail/commit/884eb611627ef2bd5a2e20e02009… PatchThird Party Advisory
- https://github.com/roundcube/roundcubemail/compare/1.4.4...1.4.5 Patch
- https://github.com/roundcube/roundcubemail/commit/884eb611627ef2bd5a2e20e02009… PatchThird Party Advisory
- https://github.com/roundcube/roundcubemail/compare/1.4.4...1.4.5 Patch
- https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2020-13965-Cross%… ExploitThird Party Advisory
- https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2020-13965-Cross%… ExploitThird Party Advisory
- https://github.com/roundcube/roundcubemail/releases/tag/1.3.12 Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.4.5 Release Notes