MEDIUM

CVE-2023-5631

Debian Debian Linux 2023-10-18 CVSS v3.1
CVSS
5.4
KEV

Description

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker

to load arbitrary JavaScript code.

Summary dbcve.org

Stored XSS vulnerability in Roundcube's washtml.php component that fails to properly sanitize SVG documents embedded in HTML emails, allowing attackers to inject malicious JavaScript that executes when users view the crafted email.

Mitigation

Upgrade to patched Roundcube versions (1.4.15, 1.5.5, or 1.6.4) or apply the vendor patch to rcube_washtml.php; consider disabling HTML email rendering as defense-in-depth while patching.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

75.87%
Probability of exploitation in next 30 days
99.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE