CVE-2024-37383
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- June 07, 2024
- Published Date
- June 07, 2024
- Last Updated
- October 24, 2024
- Vendor
- n/a
- Product
- n/a
- Description
- Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
CVSS Scores
CVSS v3.1
6.1 - MEDIUM
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
SSVC Information
- Exploitation
- active
- Technical Impact
- partial
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2024-10-24 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
bartfroklage/CVE-2024-37383-POC
Type: github • Created: 2024-10-24 04:01:03 UTC • Stars: 5
Proof of concept for CVE-2024-37383