Impact
The vulnerability is a stored cross‑site scripting flaw localized in the "Add to address book" action of Roundcube Webmail. Malicious input placed into an address book entry is persisted and later executed in the browser of any user who views that entry, allowing an attacker to run arbitrary JavaScript in the victim’s context, potentially leading to session hijacking, data theft or defacement.
Affected Systems
Roundcube Webmail versions earlier than 1.6.18 and any 1.7 series release before 1.7.3 are affected. All editions that expose the Add to address book feature are vulnerable.
Risk and Exploitability
Based on the description, the likely attack vector is an authenticated user inserting malicious script into an address book entry, after which the script runs for anyone displaying that entry. The CVSS score of 5.4 indicates moderate severity. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, so the probability of widespread exploitation is uncertain, but storage XSS remains a significant threat to compromised web interfaces.
OpenCVE Enrichment
Debian DLA
Debian DSA