Roundcube Webmail
cpe:2.3:a:roundcube:roundcube_webmail:*:*:*:*:*:*:*, +1 more
- >= 1.6, < 1.6.16
- >= 1.7, < 1.7.1
A stored cross-site scripting vulnerability has been identified in Roundcube Webmail versions 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1. The issue arises from an unsanitized subject field in the draft restore dialog, which could lead to HTML and CSS injection in shared mailboxes.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user accessing the shared mailbox.
To reproduce this vulnerability, create a draft email in a shared mailbox and enter an unsanitized value in the subject field. When the draft is saved and later restored, the unsanitized subject will be injected as HTML, executing any embedded scripts.
Users are advised to update to Roundcube Webmail versions 1.6.16 or 1.7.1.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.