Junglewise Threat Intelligence

CVE-2020-13965: Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

CVE-2020-13965 · Severity: critical · CVSS 6.1 · Exploited in the wild · Published 2024-06-26

Technologies: Roundcube Webmail. Vendors: Roundcube.

Executive brief

Roundcube Webmail contains a cross-site scripting (XSS) vulnerability when handling XML attachments. The application incorrectly allows text/xml files to be previewed, enabling remote attackers to execute malicious scripts in the context of the user's session via a specially crafted XML file.

Affected products

  • Roundcube Webmail before 1.3.12, 1.4.x before 1.4.5

Timeline

  • 2020-06-02: patched: Security updates 1.4.5 and 1.3.12 released by vendor.
  • 2024-06-26: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats