Junglewise Threat Intelligence

CVE-2024-37383: RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability

CVE-2024-37383 · Severity: critical · CVSS 6.1 · Exploited in the wild · Published 2024-10-24

Technologies: Roundcube Webmail, Debian Linux. Vendors: Roundcube, Debian.

Executive brief

Roundcube Webmail is vulnerable to Cross-Site Scripting (XSS) due to improper neutralization of SVG animate attributes. A remote attacker can exploit this by sending a malicious email that executes arbitrary JavaScript in the context of the user's browser session.

Affected products

  • Roundcube Webmail before 1.5.7, 1.6.x before 1.6.7
  • Debian Debian Linux 10.0

Timeline

  • 2024-06-07: disclosed: Initial NVD publication date
  • 2024-06-07: patched: Roundcube releases 1.5.7 and 1.6.7 to address the vulnerability
  • 2024-10-24: kev added: CISA adds CVE-2024-37383 to the Known Exploited Vulnerabilities (KEV) catalog

Related threats