PT-2013-5708 · Roundcube · Roundcube Webmail

Published

2013-08-29

·

Updated

2013-08-29

·

CVE-2013-5646

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Roundcube webmail version 1.0-git
Description A cross-site scripting (XSS) issue allows remote authenticated users to inject arbitrary web script or HTML via the Name field of an addressbook group.
Recommendations For Roundcube webmail version 1.0-git, consider restricting access to the addressbook group feature until a fix is available, and avoid using the Name field to inject web script or HTML.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-5646

Affected Products

Roundcube Webmail