MEDIUM
CVE-2023-5631
CVSS
5.4
KEV
Description
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker
to load arbitrary JavaScript code.
Summary dbcve.org
Stored XSS vulnerability in Roundcube's washtml.php component that fails to properly sanitize SVG documents embedded in HTML emails, allowing attackers to inject malicious JavaScript that executes when users view the crafted email.
Mitigation
Upgrade to patched Roundcube versions (1.4.15, 1.5.5, or 1.6.4) or apply the vendor patch to rcube_washtml.php; consider disabling HTML email rendering as defense-in-depth while patching.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
75.87%
Probability of exploitation in next 30 days
99.5th percentile
References
http://www.openwall.com/lists/oss-security/2023/11/01/1
Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/11/01/3
Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/11/17/2
Mailing List, Third Party Advisory
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1054079
Mailing List, Patch
https://github.com/roundcube/roundcubemail/commit/41756cc3331b495cc0b71886984474dc529dd31d
Patch
https://github.com/roundcube/roundcubemail/commit/6ee6e7ae301e165e2b2cb703edf75552e5376613
Patch
https://github.com/roundcube/roundcubemail/issues/9168
Exploit, Issue Tracking
https://github.com/roundcube/roundcubemail/releases/tag/1.4.15
Release Notes
https://github.com/roundcube/roundcubemail/releases/tag/1.5.5
Release Notes
https://github.com/roundcube/roundcubemail/releases/tag/1.6.4
Release Notes
https://lists.debian.org/debian-lts-announce/2023/10/msg00035.html
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LK67Q46OIEGJCRQUBHKLH3IIJTBNGGX4/
Mailing List
https://roundcube.net/news/2023/10/16/security-update-1.6.4-released
Release Notes
https://roundcube.net/news/2023/10/16/security-updates-1.5.5-and-1.4.15
Release Notes
https://www.debian.org/security/2023/dsa-5531
Mailing List
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-5631
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.