MEDIUM

CVE-2024-37383

Debian Debian Linux 2024-06-07 CVSS v3.1
CVSS
6.1
KEV

Description

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

Summary dbcve.org

Roundcube Webmail fails to properly sanitize SVG content containing animate attributes, allowing an attacker to inject malicious scripts that execute in the context of the victim's browser. This is a stored XSS vulnerability where crafted SVG markup in email content or attachments is rendered without adequate filtering.

Mitigation

Update Roundcube Webmail to version 1.5.7, 1.6.7, or later to patch the SVG sanitization vulnerability.

Patch Commit

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

73.3%
Probability of exploitation in next 30 days
99.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE