Junglewise Threat Intelligence

CVE-2023-5631: Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

CVE-2023-5631 · Severity: critical · CVSS 5.4 · Exploited in the wild · Published 2023-10-26

Technologies: Roundcube Webmail. Vendors: Roundcube.

Executive brief

Roundcube Webmail contains a stored cross-site scripting (XSS) vulnerability in the rcube_washtml.php component. A remote attacker can execute arbitrary JavaScript code by sending a specially crafted HTML email message containing a malicious SVG document.

Affected products

  • Roundcube Roundcube Webmail before 1.4.15, 1.5.x before 1.5.5, 1.6.x before 1.6.4

Timeline

  • 2023-10-16: patched: Vendor released versions 1.6.4, 1.5.5, and 1.4.15 to address the vulnerability.
  • 2023-10-26: disclosed: CVE published and added to CISA KEV catalog.
  • 2023-10-26: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
  • 2023-10-26: exploited: Reported as exploited in the wild.

Related threats