CVE-2015-8864 REJECTED

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-4068.

EPSS 0.48% · 65.0th percentile

Risk Scores

EPSS Score
0.48%
65.0th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSroundcube0, 1.1.1+dfsg.1-2, 1.1.2+dfsg.1-5
Ubuntu:18.04:LTSroundcube0, 1.3.0+dfsg.1-1, 1.3.1+dfsg.1-1

Timeline

References

Open in Interactive Console →