XSS Vulnerability in Roundcube Webmail by Roundcube
CVE-2021-26925

5.4MEDIUM

Key Information:

Vendor

Roundcube

Status
Vendor
CVE Published:
9 February 2021

What is CVE-2021-26925?

A vulnerability exists in Roundcube Webmail versions prior to 1.4.11 that allows attackers to exploit XSS through specially crafted Cascading Style Sheets (CSS) token sequences. This could potentially lead to unauthorized actions on behalf of users when they interact with malicious HTML emails, underscoring the importance of updating to the latest version to protect against possible threats.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.