Executive brief
Roundcube Webmail contains a stored cross-site scripting (XSS) vulnerability in the rcube_washtml.php component. A remote attacker can execute arbitrary JavaScript code by sending a specially crafted HTML email message containing a malicious SVG document.
Affected products
- Roundcube Roundcube Webmail before 1.4.15, 1.5.x before 1.5.5, 1.6.x before 1.6.4
Timeline
- 2023-10-16: patched: Vendor released versions 1.6.4, 1.5.5, and 1.4.15 to address the vulnerability.
- 2023-10-26: disclosed: CVE published and added to CISA KEV catalog.
- 2023-10-26: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
- 2023-10-26: exploited: Reported as exploited in the wild.