PT-2021-17180 · Roundcube+1 · Roundcube+1
Mateusz Szymaniec
·
Published
2021-02-09
·
Updated
2024-03-06
·
CVE-2021-26925
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Roundcube versions prior to 1.4.11
Description:
The issue allows for an XSS attack through crafted Cascading Style Sheets (CSS) token sequences during the rendering of HTML email. This can occur when an attacker sends a specially designed email that exploits this weakness.
Recommendations:
For versions prior to 1.4.11, update to version 1.4.11 or later to resolve the issue. As a temporary workaround, consider restricting the rendering of HTML emails or disabling the use of CSS in emails until a patch is applied. Avoid using potentially vulnerable CSS token sequences in email templates until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Roundcube