Roundcube Webmail
cpe:2.3:a:roundcube:roundcube:*:*:*:*:*:*:*, +2 more
- < 1.6.12
- < 1.5.12
This vulnerability is being actively exploited in the wild.
A Cross-Site Scripting (XSS) vulnerability has been identified in Roundcube Webmail versions prior to 1.5.12 and 1.6 through 1.6.12. The issue arises from the handling of the animate tag within SVG documents, which can be exploited to inject malicious scripts.
Exploitation of this vulnerability allows for Cross-Site Scripting attacks, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
To reproduce this vulnerability, create an SVG file that includes an animate tag. The animate tag can be used to reference JavaScript URLs, such as 'javascript:alert(1)'. When this SVG is processed by Roundcube Webmail, the injected script will be executed, demonstrating the Cross-Site Scripting vulnerability.
Users are advised to update to Roundcube Webmail versions 1.6.12 or 1.5.12.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.