Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-5631
HistoryOct 18, 2023 - 12:00 a.m.

CVE-2023-5631

2023-10-1800:00:00
ubuntu.com
ubuntu.com
104
cve-2023-5631
roundcube
stored xss
html e-mail
svg
remote attacker
debian
bug
unix

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.007 Low

EPSS

Percentile

80.1%

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows
stored XSS via an HTML e-mail message with a crafted SVG document because
of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a
remote attacker to load arbitrary JavaScript code.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchroundcube< 1.3.6+dfsg.1-1ubuntu0.1~esm4UNKNOWN
ubuntu20.04noarchroundcube< 1.4.3+dfsg.1-1ubuntu0.1~esm4UNKNOWN
ubuntu22.04noarchroundcube< 1.5.0+dfsg.1-2ubuntu0.1~esm3UNKNOWN
ubuntu23.10noarchroundcube< 1.6.2+dfsg-1ubuntu0.2UNKNOWN

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.007 Low

EPSS

Percentile

80.1%