Executive brief
Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability in program/lib/Roundcube/rcube_string_replacer.php. The flaw allows attackers to execute malicious scripts via crafted links in plain/text email messages, potentially leading to information disclosure.
Affected products
- Roundcube Webmail < 1.4.14, 1.5.x < 1.5.4, 1.6.x < 1.6.3
Timeline
- 2023-09-15: patched: Vendor released security update 1.6.3
- 2023-09-22: disclosed: NVD Published Date
- 2024-02-12: kev added: CISA added to Known Exploited Vulnerabilities Catalog