6.1

CVE-2020-35730

Warnung
Medienbericht
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Roundcube ≫ Webmail Version < 1.2.13
Roundcube ≫ Webmail Version >= 1.3.0 < 1.3.16
Roundcube ≫ Webmail Version >= 1.4 < 1.4.10
Fedoraproject ≫ Fedora Version 32
Fedoraproject ≫ Fedora Version 33
Debian ≫ Debian Linux Version 9.0

22.06.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog

Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

Schwachstelle

Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link reference element that is mishandled by linkref_addinindex in rcube_string_replacer.php.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 32.69% 0.982
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CISA-ADP 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
24.09.2026 15:47
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=978491
Mailing List
Issue Tracking
https://github.com/roundcube/roundcubemail/compare/1.4.9...1.4.10
Patch
https://github.com/roundcube/roundcubemail/releases/tag/1.2.13
Release Notes
https://github.com/roundcube/roundcubemail/releases/tag/1.3.16
Release Notes
https://github.com/roundcube/roundcubemail/releases/tag/1.4.10
Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCEU4BM5WGIDJWP6Z4PCH62ZMH57QYM2/
Mailing List
Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HMLIZWKMTRCLU7KZLEQHELS4INXJ7X5Q/
Mailing List
Release Notes
https://roundcube.net/download/
Product
https://www.alexbirnberg.com/roundcube-xss.html
Broken Link
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-35730
US Government Resource