CVE-2020-15562 PUBLISHED

An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists.

EPSS 0.86% · 74.9th percentile

Risk Scores

EPSS Score
0.86%
74.9th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:20.04:LTSroundcube1.4.3+dfsg.1-1ubuntu0.1~esm1, 0, 1.3.8+dfsg.1-2
Ubuntu:Pro:18.04:LTSroundcube1.3.0+dfsg.1-1, 1.3.1+dfsg.1-1, 1.3.3+dfsg.1-1

Timeline

References

Open in Interactive Console →