CVE-2020-16145Cross-site Scripting in Webmail

Severity
6.1MEDIUMNVD
EPSS
0.7%
top 27.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12
Latest updateAug 8

Description

Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

NVDroundcube/webmail1.4.01.4.8+1

Also affects: Fedora 31, 32

Patches

🔴Vulnerability Details

4
OSV
roundcube vulnerabilities2022-08-08
GHSA
GHSA-fjwm-m9vj-wvr8: Roundcube Webmail before 12022-05-24
OSV
CVE-2020-16145: Roundcube Webmail before 12020-08-12
CVEList
CVE-2020-16145: Roundcube Webmail before 12020-08-12

📋Vendor Advisories

2
Ubuntu
Roundcube Webmail vulnerabilities2022-08-08
Debian
CVE-2020-16145: roundcube - Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages dur...2020

💬Community

2
Bugzilla
CVE-2020-16145 roundcubemail: xss via HTML messages with malicious svg content2020-08-12
Bugzilla
CVE-2020-16145 roundcubemail: xss via HTML messages with malicious svg content [fedora-all]2020-08-12
CVE-2020-16145 — Cross-site Scripting in Webmail | cvebase