Junglewise Threat Intelligence

CVE-2023-43770: Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

CVE-2023-43770 · Severity: critical · CVSS 6.1 · Exploited in the wild · Published 2024-02-12

Technologies: Roundcube Webmail. Vendors: Roundcube.

Executive brief

Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability in program/lib/Roundcube/rcube_string_replacer.php. The flaw allows attackers to execute malicious scripts via crafted links in plain/text email messages, potentially leading to information disclosure.

Affected products

  • Roundcube Webmail < 1.4.14, 1.5.x < 1.5.4, 1.6.x < 1.6.3

Timeline

  • 2023-09-15: patched: Vendor released security update 1.6.3
  • 2023-09-22: disclosed: NVD Published Date
  • 2024-02-12: kev added: CISA added to Known Exploited Vulnerabilities Catalog

Related threats