CVE-2023-5631
בינונית 5.4 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.
מדדים
- CVSS 3.1
-
5.4 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 76% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-79
מוצרים מושפעים
roundcube: webmail; debian: debian linux; fedoraproject: fedora
קישורים
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1054079 Mailing ListPatch
- https://github.com/roundcube/roundcubemail/commit/41756cc3331b495cc0b718869844… Patch
- https://github.com/roundcube/roundcubemail/commit/6ee6e7ae301e165e2b2cb703edf7… Patch
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1054079 Mailing ListPatch
- https://github.com/roundcube/roundcubemail/commit/41756cc3331b495cc0b718869844… Patch
- https://github.com/roundcube/roundcubemail/commit/6ee6e7ae301e165e2b2cb703edf7… Patch
- https://github.com/roundcube/roundcubemail/issues/9168 ExploitIssue Tracking
- https://github.com/roundcube/roundcubemail/issues/9168 ExploitIssue Tracking
- http://www.openwall.com/lists/oss-security/2023/11/01/1 Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/11/01/3 Mailing ListThird Party Advisory