Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Aidan Marlin

#42750of 53,633
6.1Total CVSS
Vulnerabilities · 1
PT-2018-14862
6.1
2018-11-03
Roundcube · Roundcube · CVE-2018-19206
**Name of the Vulnerable Software and Affected Versions** Roundcube versions prior to 1.3.8 ALT Linux (affected versions not specified) **Description** The issue allows for XSS via crafted use of `<svg><style>`, as demonstrated by an `onload` attribute in a `BODY` element, within an HTML attachment. This can lead to potential exploitation. **Recommendations** For Roundcube versions prior to 1.3.8, update to version 1.3.8 or later to resolve the issue. For ALT Linux, at the moment, there is no information about a newer version that contains a fix for this vulnerability.