Executive brief
Roundcube Webmail is vulnerable to Cross-Site Scripting (XSS) due to improper neutralization of SVG animate attributes. A remote attacker can exploit this by sending a malicious email that executes arbitrary JavaScript in the context of the user's browser session.
Affected products
- Roundcube Webmail before 1.5.7, 1.6.x before 1.6.7
- Debian Debian Linux 10.0
Timeline
- 2024-06-07: disclosed: Initial NVD publication date
- 2024-06-07: patched: Roundcube releases 1.5.7 and 1.6.7 to address the vulnerability
- 2024-10-24: kev added: CISA adds CVE-2024-37383 to the Known Exploited Vulnerabilities (KEV) catalog