CVE-2023-43770
בינונית 6.1 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.
מדדים
- CVSS 3.1
-
6.1 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 58% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-79
מוצרים מושפעים
roundcube: webmail; debian: debian linux
קישורים
- https://github.com/roundcube/roundcubemail/commit/e92ec206a886461245e1672d8530… Patch
- https://github.com/roundcube/roundcubemail/commit/e92ec206a886461245e1672d8530… Patch
- https://lists.debian.org/debian-lts-announce/2023/09/msg00024.html Mailing List
- https://roundcube.net/news/2023/09/15/security-update-1.6.3-released Release Notes
- https://lists.debian.org/debian-lts-announce/2023/09/msg00024.html Mailing List
- https://roundcube.net/news/2023/09/15/security-update-1.6.3-released Release Notes
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource