← לוח פגיעויות

CVE-2023-5631

בינונית 5.4 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.

מדדים

CVSS 3.1
5.4 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS — סבירות ניצול
76% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-79

מוצרים מושפעים

roundcube: webmail; debian: debian linux; fedoraproject: fedora

קישורים