CVE-2015-8864Cross-site Scripting in Webmail

CWE-79Cross-site Scripting13 documents6 sources
Severity
6.1MEDIUMNVD
EPSS
0.5%
top 34.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateMay 14

Description

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-4068.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages5 packages

Debianroundcube/roundcube_webmail< 1.2.1+dfsg.1-1+7
NVDroundcube/webmail1.0.8+2
NVDroundcube/roundcube_webmail1.1.1, 1.1.2, 1.1.3+2
NVDopensuse/leap42.1
NVDopensuse/opensuse13.1, 13.2+1

Patches

🔴Vulnerability Details

6
GHSA
GHSA-4rqp-f36w-28hw: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 12022-05-14
GHSA
GHSA-69rv-gvqx-4x9h: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 12022-05-14
OSV
CVE-2016-4068: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 12017-04-13
OSV
CVE-2015-8864: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 12017-04-13
CVEList
CVE-2016-4068: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 12017-04-13

📋Vendor Advisories

2
Debian
CVE-2016-4068: roundcube - Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1...2016
Debian
CVE-2015-8864: roundcube - Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1...2015

💬Community

3
Bugzilla
CVE-2015-2181 CVE-2015-8864 CVE-2016-4068 CVE-2016-4069 roundcubemail: security issues fixed in version 1.0.9 [fedora-all]2016-04-25
Bugzilla
CVE-2015-2181 CVE-2015-8864 CVE-2016-4068 CVE-2016-4069 roundcubemail: security issues fixed in version 1.0.92016-04-25
Bugzilla
CVE-2015-2181 CVE-2015-8864 CVE-2016-4068 CVE-2016-4069 roundcubemail: security issues fixed in version 1.0.9 [epel-all]2016-04-25
CVE-2015-8864 — Cross-site Scripting in Webmail | cvebase