CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2023-5631

🔥 Known Exploited (CISA KEV)MEDIUM
6.1
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2023-10-18
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.

Affected Platforms (CPE)

📦
Roundcube

Webmail

< 1.4.15>= 1.5.0 and < 1.5.5>= 1.6.0 and < 1.6.4
💻
Debian

Debian Linux

= 10.0= 11.0= 12.0
💻
Fedoraproject

Fedora

= 39

References & Advisories

相關資安分析文章

相關漏洞威脅