vendor:
Roundcube Webmail
by:
AmirZargham
6.1
CVSS
HIGH
Stored Cross Site Scripting (XSS)
79
CWE
Product Name: Roundcube Webmail
Affected Version From: 1.6
Affected Version To: 38869
Patch Exists: NO
Related CWE: CVE-2024-37383
CPE: a:roundcube:roundcubemail
Platforms Tested: Firefox, Chrome
2024
Roundcube Webmail 1.6.6 – Stored Cross Site Scripting (XSS)
The Roundcube Webmail email client before version 1.5.6 or between versions 1.6 and 1.6.6 is vulnerable to stored XSS (Cross Site Scripting) identified as CVE-2024-37383. This vulnerability allows malicious attackers to execute JavaScript code on a user's page by sending a specially crafted email.
Mitigation:
To mitigate this vulnerability, users are advised to update Roundcube Webmail to version 1.5.6 or above to prevent exploitation of the stored XSS issue.