[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256040

 
 

909

 
 

199103

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-5645Date: (C)2013-08-30   (M)2023-12-22


Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before 0.9.3 allow user-assisted remote attackers to inject arbitrary web script or HTML via the body of a message visited in (1) new or (2) draft mode, related to compose.inc; and (3) might allow remote authenticated users to inject arbitrary web script or HTML via an HTML signature, related to save_identity.inc.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
http://trac.roundcube.net/changeset/93b0a30c1c8aa29d862b587b31e52bcc344b8d16/github
http://trac.roundcube.net/changeset/ce5a6496fd6039962ba7424d153278e41ae8761b/github
http://trac.roundcube.net/ticket/1489251
http://trac.roundcube.net/wiki/Changelog#RELEASE0.9.3
openSUSE-SU-2013:1420

CPE    52
cpe:/a:roundcube:webmail:0.8.2
cpe:/a:roundcube:webmail:0.3:beta
cpe:/a:roundcube:webmail:0.1:beta2
cpe:/a:roundcube:webmail:0.8.3
...
CWE    1
CWE-79
OVAL    1
oval:org.secpod.oval:def:1300232

© SecPod Technologies