Cross-Site Scripting Vulnerability in Roundcube Webmail Affects Webmail Platforms
CVE-2020-12625
6.1MEDIUM
What is CVE-2020-12625?
A Cross-Site Scripting vulnerability has been identified in Roundcube Webmail prior to version 1.4.4. The issue lies in the processing of HTML messages which allows malicious JavaScript code to be executed if the CDATA section of the message contains harmful scripts. This can lead to unauthorized access and manipulation of user sessions, posing a significant security risk for affected users.