PT-2023-6427 · Roundcube+4 · Roundcube+4

Aleksander Machniak

+2

·

Published

2019-11-09

·

Updated

2026-03-12

·

CVE-2023-5631

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Roundcube versions 1.4.15 and earlier, 1.5.x before 1.5.5, and 1.6.x before 1.6.4
Description The issue allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code. The vulnerability has been exploited in the wild by groups such as Winter Vivern to target government entities and steal emails. The attackers send a specially crafted email message that includes a malicious payload, which is then executed on the victim's computer.
Recommendations For versions 1.4.15 and earlier, update to version 1.4.15 or later. For versions 1.5.x before 1.5.5, update to version 1.5.5 or later. For versions 1.6.x before 1.6.4, update to version 1.6.4 or later. As a temporary workaround, consider disabling the rcube washtml.php function until a patch is available. Restrict access to the vulnerable program/lib/Roundcube module to minimize the risk of exploitation. Avoid using the rcube washtml.php behavior in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3109
ALT-PU-2020-1898
ALT-PU-2020-2367
ALT-PU-2021-3558
ALT-PU-2022-1073
ALT-PU-2023-6826
ALT-PU-2025-1825
ALT-PU-2025-8283
BDU:2023-07143
BIT-ROUNDCUBE-2023-5631
CVE-2023-5631
DLA-3630-1
DSA-5531-1
MGASA-2023-0332
OPENSUSE-SU-2023:0345-1
OPENSUSE-SU-2024:13365-1
USN-6848-1

Affected Products

Alt Linux
Linuxmint
Red Os
Roundcube
Ubuntu