Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-5631


Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.


Published

2023-10-18T15:15:08.727

Last Modified

2025-03-19T20:57:50.170

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application roundcube webmail < 1.4.15 Yes
Application roundcube webmail < 1.5.5 Yes
Application roundcube webmail < 1.6.4 Yes
Operating System debian debian_linux 10.0 Yes
Operating System debian debian_linux 11.0 Yes
Operating System debian debian_linux 12.0 Yes
Operating System fedoraproject fedora 39 Yes

References