Impact
Roundcube Webmail versions prior to 1.6.18 and 1.7.x before 1.7.3 suffer from improper sanitization of the SVG animate "by" attribute, which allows an attacker to craft an SVG that bypasses the remote image blocking filter. This flaw can lead to information disclosure or privilege escalation if a user opens the crafted content. The CVSS score of 5.8 indicates a moderate severity.
Affected Systems
The affected product is Roundcube Webmail. Users running any version before 1.6.18 or before 1.7.3 are susceptible. The exact models are Roundcube versions 1.6.x prior to 1.6.18 and 1.7.x prior to 1.7.3.
Risk and Exploitability
With a CVSS score of 5.8 and no EPSS data, the likelihood of exploitation is currently unknown, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, where an attacker sends a malicious SVG attachment or URL to a victim. Once the victim views the content, the remote image blocking bypass can reveal sensitive data or elevate privileges.
OpenCVE Enrichment