PT-2023-6963 · Roundcube+3 · Roundcube+3

Rene Rehme

·

Publicado

2023-11-05

·

Atualizado

2024-08-21

·

CVE-2023-47272

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Roundcube versions 1.5.x through 1.5.5 Roundcube versions 1.6.x through 1.6.4
Description The issue is related to improper input neutralization during web page creation, which can lead to cross-site scripting (XSS) attacks via a Content-Type or Content-Disposition header, specifically when used for attachment preview or download. This can allow a remote attacker to conduct cross-site scripting attacks.
Recommendations For Roundcube versions 1.5.x through 1.5.5, update to version 1.5.6 or later. For Roundcube versions 1.6.x through 1.6.4, update to version 1.6.5 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07982
BIT-ROUNDCUBE-2023-47272
CVE-2023-47272
DLA-3683-1
DSA-5572-1
MGASA-2023-0332
OPENSUSE-SU-2024:0257-1
OPENSUSE-SU-2024:13401-1
USN-6848-1

Produtos afetados

Linuxmint
Red Os
Roundcube
Ubuntu