CVE-2020-35730
בינונית 6.1 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.
מדדים
- CVSS 3.1
-
6.1 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 33% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-79
מוצרים מושפעים
roundcube: webmail; fedoraproject: fedora; debian: debian linux
קישורים
- https://github.com/roundcube/roundcubemail/compare/1.4.9...1.4.10 Patch
- https://github.com/roundcube/roundcubemail/compare/1.4.9...1.4.10 Patch
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=978491 Issue TrackingMailing List
- https://github.com/roundcube/roundcubemail/releases/tag/1.2.13 Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.3.16 Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.4.10 Release Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap… Mailing ListRelease Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap… Mailing ListRelease Notes
- https://roundcube.net/download/ Product
- https://www.alexbirnberg.com/roundcube-xss.html Broken Link