CVE-2012-1253Cross-site Scripting in Webmail

Severity
2.6LOWNVD
EPSS
0.3%
top 51.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 4
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.7, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via vectors involving an embedded image attachment.

CVSS vector

AV:N/AC:H/C:N/I:P/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages1 packages

NVDroundcube/webmail0.6+15

🔴Vulnerability Details

3
GHSA
GHSA-3mvr-3jc2-mgf4: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 02022-05-17
OSV
CVE-2012-1253: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 02012-06-04
CVEList
CVE-2012-1253: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 02012-06-04

📋Vendor Advisories

2
Debian
CVE-2012-1253: roundcube - Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.7, when I...2012
Red Hat
kernel: no access restrictions of /proc/pid/* after setuid program exec2011-02-07

💬Community

3
Bugzilla
CVE-2012-1253 roundcubemail: XSS flaw fixed in 0.72012-06-04
Bugzilla
CVE-2012-1253 roundcubemail: XSS flaw fixed in 0.7 [epel-all]2012-06-04
Bugzilla
CVE-2012-1253 roundcubemail: XSS flaw fixed in 0.7 [fedora-16]2012-06-04
CVE-2012-1253 — Cross-site Scripting in Webmail | cvebase