Executive brief
Roundcube Webmail contains a cross-site scripting (XSS) vulnerability where JavaScript in a link reference element within a plain text email is mishandled by the linkref_addindex function in rcube_string_replacer.php. This allows a remote attacker to execute arbitrary script in the context of the victim's browser session.
Affected products
- Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, 1.4.x before 1.4.10
Timeline
- 2020-12-27: disclosed: Initial CVE assignment/disclosure date based on CVE ID year and external references
- 2023-06-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-06-22: exploited: Confirmed exploited in the wild per CISA KEV entry