PT-2024-4655 · Unknown+4 · Roundcube Webmail+4

Lutz Wolf

+1

·

Published

2019-11-09

·

Updated

2025-12-06

·

CVE-2024-37383

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Roundcube Webmail versions prior to 1.5.7 and 1.6.x prior to 1.6.7
Description: The issue is related to a stored cross-site scripting vulnerability in the Roundcube webmail software, allowing an attacker to execute JavaScript code on the user's page. This vulnerability can be exploited by sending a malicious email to a user, which then executes the malicious code when the email is opened. The vulnerability is caused by improper filtering of SVG tags, specifically the animate attributes. It is reported that over 2.7 million services are potentially affected, and there have been real-world incidents where this issue was exploited to steal credentials and compromise emails.
Recommendations: For versions prior to 1.5.7 and 1.6.x prior to 1.6.7, update to version 1.5.7 or 1.6.7 or later to resolve the issue. As a temporary workaround, consider disabling the use of SVG elements in emails until a patch is applied. Restrict access to the vulnerable Roundcube webmail software to minimize the risk of exploitation. Avoid using the animate attributes in SVG elements in emails until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3109
ALT-PU-2020-1898
ALT-PU-2020-2367
ALT-PU-2021-3558
ALT-PU-2022-1073
ALT-PU-2023-6826
ALT-PU-2025-1825
ALT-PU-2025-8283
BDU:2024-05163
CVE-2024-37383
DLA-3835-1
DSA-5714-1
USN-6848-1

Affected Products

Alt Linux
Linuxmint
Red Os
Roundcube Webmail
Ubuntu