Executive brief
Roundcube Webmail contains a cross-site scripting (XSS) vulnerability when handling XML attachments. The application incorrectly allows text/xml files to be previewed, enabling remote attackers to execute malicious scripts in the context of the user's session via a specially crafted XML file.
Affected products
- Roundcube Webmail before 1.3.12, 1.4.x before 1.4.5
Timeline
- 2020-06-02: patched: Security updates 1.4.5 and 1.3.12 released by vendor.
- 2024-06-26: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.