6.1 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
0.007 Low
EPSS
Percentile
80.1%
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows
stored XSS via an HTML e-mail message with a crafted SVG document because
of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a
remote attacker to load arbitrary JavaScript code.
github.com/roundcube/roundcubemail/commit/41756cc3331b495cc0b71886984474dc529dd31d (1.6.4)
github.com/roundcube/roundcubemail/commit/6ee6e7ae301e165e2b2cb703edf75552e5376613
github.com/roundcube/roundcubemail/releases/tag/1.4.15
github.com/roundcube/roundcubemail/releases/tag/1.5.5
github.com/roundcube/roundcubemail/releases/tag/1.6.4
launchpad.net/bugs/cve/CVE-2023-5631
nvd.nist.gov/vuln/detail/CVE-2023-5631
security-tracker.debian.org/tracker/CVE-2023-5631
ubuntu.com/security/notices/USN-6848-1
www.cve.org/CVERecord?id=CVE-2023-5631