Impact
A crafted plain‑text email can inject malicious JavaScript that is stored by the Roundcube Webmail application and executed when a victim opens or previews the message. This stored cross‑scripting allows the attacker to run arbitrary code within the victim’s authenticated browser context, potentially stealing session cookies, defacing content or performing actions on behalf of the user.
Affected Systems
Roundcube Webmail clients prior to version 1.6.17 and any 1.7.x version before 1.7.2 are vulnerable. The issue affects all installations that accept plain‑text email, regardless of hosting environment or operating system.
Risk and Exploitability
The CVSS score is 7.2, indicating high severity, and the EPSS score of less than 1% suggests low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Attackers can achieve the exploit with zero user interaction beyond opening or previewing the malicious email, typically after the victim is already authenticated. The weakness is CWE‑79 and requires patching the application’s input handling and output encoding.
OpenCVE Enrichment
Debian DLA
Debian DSA