⚠ Actively exploited
Added to CISA KEV on 2024-10-24. Federal agencies required to patch by 2024-11-14. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..
CVE-2024-37383 — Cross-site Scripting in Webmail
Severity
6.1MEDIUMNVD
EPSS
64.0%
top 1.56%
CISA KEV
KEV
Added 2024-10-24
Due 2024-11-14
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedJun 7
KEV addedOct 24
KEV dueNov 14
Latest updateJan 8
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7
Patches
🔴Vulnerability Details
4💥Exploits & PoCs
1🔍Detection Rules
1📋Vendor Advisories
4Debian▶
CVE-2024-37383: roundcube - Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate...↗2024