CVE-2020-16145 PUBLISHED

Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.

EPSS 0.70% · 72.0th percentile

Risk Scores

EPSS Score
0.70%
72.0th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSroundcube0, 1.3.0+dfsg.1-1, 1.3.1+dfsg.1-1
Ubuntu:Pro:20.04:LTSroundcube0, 1.3.8+dfsg.1-2, 1.3.10+dfsg.1-1

Timeline

References

Open in Interactive Console →