CVE-2023-5631

Stored XSS vulnerability in Roundcube

Basic Information

CVE State
PUBLISHED
Reserved Date
October 18, 2023
Published Date
October 18, 2023
Last Updated
February 13, 2025
Vendor
Roundcube
Product
Roundcubemail
Description
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.

CVSS Scores

CVSS v3.1

6.1 - MEDIUM

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2023-10-26 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2023-10-26 00:00:00 UTC