Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker
to load arbitrary JavaScript code.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: ESET
Published: 2023-10-18T14:51:18.443Z
Updated: 2024-08-02T08:07:32.513Z
Reserved: 2023-10-18T06:50:57.504Z
Link: CVE-2023-5631
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-10-18T15:15:08.727
Modified: 2024-11-21T08:42:09.390
Link: CVE-2023-5631
Redhat
No data.