PT-2020-3630 · Roundcube+4 · Roundcube Webmail+4

Published

2019-11-09

·

Updated

2024-03-06

·

CVE-2020-15562

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Roundcube Webmail versions 1.2.10 and earlier, 1.3.x before 1.3.14, and 1.4.x before 1.4.7
Description The issue allows for cross-site scripting (XSS) via a crafted HTML e-mail message. This can be demonstrated by a JavaScript payload in the xmlns attribute of a HEAD element when an SVG element exists. The vulnerability is related to insufficient protection measures for web page structures, which can be exploited by a remote attacker to impact data integrity.
Recommendations For versions 1.2.10 and earlier, update to version 1.2.11 or later. For versions 1.3.x before 1.3.14, update to version 1.3.14 or later. For versions 1.4.x before 1.4.7, update to version 1.4.7 or later. As a temporary workaround, consider disabling the processing of HTML e-mail messages with SVG elements until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3109
ALT-PU-2020-2319
ALT-PU-2020-2367
BDU:2020-03977
BIT-ROUNDCUBE-2020-15562
CVE-2020-15562
DSA-4720-1
OPENSUSE-SU-2020:1516-1
OPENSUSE-SU-2020_1516-1
USN-5182-1

Affected Products

Alt Linux
Linuxmint
Roundcube Webmail
Suse
Ubuntu