vendor:
rcfilters plugin
by:
Fahimeh Rezaei
5.4
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: rcfilters plugin
Affected Version From: rcfilters plugin v2.1.6
Affected Version To: rcfilters plugin v2.1.6
Patch Exists: YES
Related CWE: CVE-2018-16736
CPE: 2.3:a:roundcube:rcfilters_plugin:2.1.6
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Roundcube version 1.0.5
2018
Roundcube rcfilters plugin 2.1.6 – Cross-Site Scripting
In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters section of the settings).
Mitigation:
Input validation should be used to prevent XSS attacks.