CVE-2013-5646Cross-site Scripting in Webmail

Severity
3.5LOWNVD
EPSS
0.2%
top 63.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 29
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows remote authenticated users to inject arbitrary web script or HTML via the Name field of an addressbook group.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 6.8 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-rjrq-995m-qvx8: Cross-site scripting (XSS) vulnerability in Roundcube webmail 12022-05-17
CVEList
CVE-2013-5646: Cross-site scripting (XSS) vulnerability in Roundcube webmail 12013-08-29

📋Vendor Advisories

1
Debian
CVE-2013-5646: roundcube - Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows rem...2013

💬Community

2
Bugzilla
CVE-2013-5645 CVE-2013-5646 roundcubemail: two XSS flaws fixed in 0.9.32013-08-23
Bugzilla
CVE-2012-5646 openshift-origin-node-util: restorer.php preg_match shell code injection2012-12-18
CVE-2013-5646 — Cross-site Scripting in Webmail | cvebase