CVE-2015-8105Cross-site Scripting in Webmail

Severity
3.5LOWNVD
EPSS
0.2%
top 60.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 10
Latest updateMay 14

Description

Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name in a drag-n-drop file upload.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 6.8 | Impact: 2.9

Affected Packages2 packages

NVDroundcube/webmail1.0.6+3
NVDopensuse/opensuse13.1, 13.2+1

🔴Vulnerability Details

3
GHSA
GHSA-v6q4-rvmf-jwq9: Cross-site scripting (XSS) vulnerability in program/js/app2022-05-14
OSV
CVE-2015-8105: Cross-site scripting (XSS) vulnerability in program/js/app2015-11-10
CVEList
CVE-2015-8105: Cross-site scripting (XSS) vulnerability in program/js/app2015-11-10

📋Vendor Advisories

1
Debian
CVE-2015-8105: roundcube - Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webma...2015

💬Community

1
Bugzilla
CVE-2015-8105 roundcubemail: XSS in drag-n-drop file uploads2015-10-29
CVE-2015-8105 — Cross-site Scripting in Webmail | cvebase