CyberSec.Space Logo
Back to CVE Browser

CVE-2020-35730

πŸ”₯ Known Exploited (CISA KEV)MEDIUM
6.1
CVSS Severity Score
EPSS Score65.4580%
EPSS Percentile97.94th
Published2020-12-28
Last Modified2025-11-04
Data SourcesNVDCISA KEVFIRST.org EPSS

Vulnerability Description

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.

Affected Platforms (CPE)

πŸ“¦
Roundcube

Webmail

< 1.2.13>= 1.3.0 and < 1.3.16>= 1.4 and < 1.4.10
πŸ’»
Fedoraproject

Fedora

= 32= 33
πŸ’»
Debian

Debian Linux

= 9.0

References & Advisories

Related Vulnerabilities