XSS Vulnerability in Roundcube Email Client Affecting Multiple Versions
CVE-2023-47272
6.1MEDIUM
What is CVE-2023-47272?
An XSS vulnerability has been identified in the Roundcube Webmail client, allowing attackers to execute malicious scripts. Specifically, this flaw affects Roundcube versions 1.5.x prior to 1.5.6 and 1.6.x prior to 1.6.5. Attackers can exploit this vulnerability by manipulating the Content-Type or Content-Disposition headers, which are involved in attachment previews or downloads. This could enable unauthorized actions or data exposure through crafted attachments.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved