MEDIUM
CVE-2024-37383
CVSS
6.1
KEV
Description
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
Summary dbcve.org
Roundcube Webmail fails to properly sanitize SVG content containing animate attributes, allowing an attacker to inject malicious scripts that execute in the context of the victim's browser. This is a stored XSS vulnerability where crafted SVG markup in email content or attachments is rendered without adequate filtering.
Mitigation
Update Roundcube Webmail to version 1.5.7, 1.6.7, or later to patch the SVG sanitization vulnerability.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
73.3%
Probability of exploitation in next 30 days
99.5th percentile
References
https://github.com/roundcube/roundcubemail/commit/43aaaa528646877789ec028d87924ba1accf5242
Patch
https://github.com/roundcube/roundcubemail/releases/tag/1.5.7
Release Notes
https://github.com/roundcube/roundcubemail/releases/tag/1.6.7
Release Notes
https://lists.debian.org/debian-lts-announce/2024/06/msg00008.html
Mailing List, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-37383
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.