CVE-2020-13965

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is...

Basic Information

CVE State
PUBLISHED
Reserved Date
June 09, 2020
Published Date
June 09, 2020
Last Updated
August 04, 2024
Vendor
n/a
Product
n/a
Description
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.

CVSS Scores

CVSS v3.1

6.1 - MEDIUM

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

SSVC Information

Exploitation
active
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (added 2024-06-26 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2024-04-13 15:49:04 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2024-06-26 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

mbadanoiu/CVE-2020-13965

Type: github • Created: 2024-04-13 15:49:04 UTC • Stars: 0

CVE-2020-13965: Cross-Site Scripting via Malicious XML Attachment in Roundcube Webmail