XSS Vulnerability in Roundcube Email Client Affecting Multiple Versions
CVE-2023-47272
6.1MEDIUM
What is CVE-2023-47272?
An XSS vulnerability has been identified in the Roundcube Webmail client, allowing attackers to execute malicious scripts. Specifically, this flaw affects Roundcube versions 1.5.x prior to 1.5.6 and 1.6.x prior to 1.6.5. Attackers can exploit this vulnerability by manipulating the Content-Type or Content-Disposition headers, which are involved in attachment previews or downloads. This could enable unauthorized actions or data exposure through crafted attachments.