CVE-2024-37383
בינונית 6.1 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
מדדים
- CVSS 3.1
-
6.1 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 73% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-79
מוצרים מושפעים
roundcube: webmail; debian: debian linux
קישורים
- https://github.com/roundcube/roundcubemail/commit/43aaaa528646877789ec028d8792… Patch
- https://github.com/roundcube/roundcubemail/commit/43aaaa528646877789ec028d8792… Patch
- https://github.com/roundcube/roundcubemail/releases/tag/1.5.7 Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.7 Release Notes
- https://lists.debian.org/debian-lts-announce/2024/06/msg00008.html Mailing ListThird Party Advisory
- https://github.com/roundcube/roundcubemail/releases/tag/1.5.7 Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.7 Release Notes
- https://lists.debian.org/debian-lts-announce/2024/06/msg00008.html Mailing ListThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource