Skip to main content
CISA Known Exploited Vulnerabilities

Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.

Added to KEV
2023-10-26
Remediation due
2023-11-16

Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA notes
https://roundcube.net/news/2023/10/16/security-update-1.6.4-released, https://roundcube.net/news/2023/10/16/security-updates-1.5.5-and-1.4.15 ; https://nvd.nist.gov/vuln/detail/CVE-2023-5631

Description

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.

Severity

CVSS 3.1 · CNA6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
SSVC · CISA-ADP
Exploitationactive
Automatableno
Technical impacttotal

Affected Products

VendorProductAffected versions
RoundcubeRoundcubemail
1.6.0 to <1.6.3
1.5.0 to <1.5.4
1.4.0 to <1.5.14
1.6.4 (unaffected)
1.5.5 (unaffected)
1.5.15 (unaffected)

More from Roundcube

Related Tool Categories

Tool categories that test for or protect against this vulnerability class.

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.