CVE-2023-47272Cross-site Scripting in Webmail

Severity
6.1MEDIUMNVD
EPSS
0.5%
top 34.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6
Latest updateFeb 16

Description

Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

NVDroundcube/webmail1.5.01.5.6+1

Also affects: Debian Linux 10.0, 11.0, 12.0, Fedora 37, 38, 39

Patches

🔴Vulnerability Details

4
OSV
roundcube vulnerabilities2024-06-25
OSV
CVE-2023-47272: Roundcube 12023-11-06
GHSA
GHSA-q2wj-pp48-fpgj: Roundcube 12023-11-06
CVEList
CVE-2023-47272: Roundcube 12023-11-05

📋Vendor Advisories

2
Ubuntu
Roundcube vulnerabilities2024-06-25
Debian
CVE-2023-47272: roundcube - Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Typ...2023

📄Research Papers

1
arXiv
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs2025-02-16
CVE-2023-47272 — Cross-site Scripting in Webmail | cvebase