XSS Vulnerability in Roundcube Email Client Affecting Multiple Versions
CVE-2023-47272

6.1MEDIUM

Key Information:

Vendor

Roundcube

Status
Vendor
CVE Published:
6 November 2023

What is CVE-2023-47272?

An XSS vulnerability has been identified in the Roundcube Webmail client, allowing attackers to execute malicious scripts. Specifically, this flaw affects Roundcube versions 1.5.x prior to 1.5.6 and 1.6.x prior to 1.6.5. Attackers can exploit this vulnerability by manipulating the Content-Type or Content-Disposition headers, which are involved in attachment previews or downloads. This could enable unauthorized actions or data exposure through crafted attachments.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-47272 : XSS Vulnerability in Roundcube Email Client Affecting Multiple Versions