Junglewise Threat Intelligence

CVE-2020-35730: Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

CVE-2020-35730 · Severity: critical · CVSS 6.1 · Exploited in the wild · Published 2023-06-22

Technologies: Roundcube Webmail. Vendors: Roundcube.

Executive brief

Roundcube Webmail contains a cross-site scripting (XSS) vulnerability where JavaScript in a link reference element within a plain text email is mishandled by the linkref_addindex function in rcube_string_replacer.php. This allows a remote attacker to execute arbitrary script in the context of the victim's browser session.

Affected products

  • Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, 1.4.x before 1.4.10

Timeline

  • 2020-12-27: disclosed: Initial CVE assignment/disclosure date based on CVE ID year and external references
  • 2023-06-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-06-22: exploited: Confirmed exploited in the wild per CISA KEV entry

Related threats