PT-2023-6963 · Roundcube+3 · Roundcube+3

Rene Rehme

·

Published

2023-11-05

·

Updated

2024-08-21

·

CVE-2023-47272

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Roundcube versions 1.5.x through 1.5.5 Roundcube versions 1.6.x through 1.6.4
Description The issue is related to improper input neutralization during web page creation, which can lead to cross-site scripting (XSS) attacks via a Content-Type or Content-Disposition header, specifically when used for attachment preview or download. This can allow a remote attacker to conduct cross-site scripting attacks.
Recommendations For Roundcube versions 1.5.x through 1.5.5, update to version 1.5.6 or later. For Roundcube versions 1.6.x through 1.6.4, update to version 1.6.5 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-07982
BIT-ROUNDCUBE-2023-47272
CVE-2023-47272
DLA-3683-1
DSA-5572-1
MGASA-2023-0332
OPENSUSE-SU-2024:0257-1
OPENSUSE-SU-2024:13401-1
USN-6848-1

Affected Products

Linuxmint
Red Os
Roundcube
Ubuntu