Cross-Site Scripting Vulnerability in Roundcube Webmail Affects Webmail Platforms
CVE-2020-12625

6.1MEDIUM

Key Information:

Vendor

Roundcube

Status
Vendor
CVE Published:
4 May 2020

Badges

👾 Exploit Exists

What is CVE-2020-12625?

A Cross-Site Scripting vulnerability has been identified in Roundcube Webmail prior to version 1.4.4. The issue lies in the processing of HTML messages which allows malicious JavaScript code to be executed if the CDATA section of the message contains harmful scripts. This can lead to unauthorized access and manipulation of user sessions, posing a significant security risk for affected users.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.