CVE-2020-13964Cross-site Scripting in Webmail

CWE-79Cross-site Scripting10 documents7 sources
Severity
6.1MEDIUMNVD
EPSS
0.9%
top 24.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 9
Latest updateAug 8

Description

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

NVDroundcube/webmail1.4.01.4.5+1

Also affects: Debian Linux 10.0, 9.0, Fedora 31, 32

Patches

🔴Vulnerability Details

4
OSV
roundcube vulnerabilities2022-08-08
GHSA
GHSA-x5vh-j6xf-cfg4: An issue was discovered in Roundcube Webmail before 12022-05-24
CVEList
CVE-2020-13964: An issue was discovered in Roundcube Webmail before 12020-06-09
OSV
CVE-2020-13964: An issue was discovered in Roundcube Webmail before 12020-06-09

📋Vendor Advisories

2
Ubuntu
Roundcube Webmail vulnerabilities2022-08-08
Debian
CVE-2020-13964: roundcube - An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4....2020

💬Community

3
Bugzilla
CVE-2020-13964 roundcubemail: XSS via the username template object [fedora-all]2020-06-18
Bugzilla
CVE-2020-13964 roundcubemail: XSS via the username template object [epel-all]2020-06-18
Bugzilla
CVE-2020-13964 roundcubemail: XSS via the username template object2020-06-18
CVE-2020-13964 — Cross-site Scripting in Webmail | cvebase