Unrated severityNVD Advisory· Published Aug 12, 2020· Updated Aug 4, 2024
CVE-2020-16145
CVE-2020-16145
Description
Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.
Affected products
10- Roundcube/Roundcube Webmaildescription
- osv-coords9 versionspkg:bitnami/roundcubepkg:rpm/opensuse/roundcubemail&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/roundcubemail&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/roundcubemail&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/roundcubemail&distro=openSUSE%20Leap%2015.4pkg:rpm/suse/roundcubemail&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/roundcubemail&distro=SUSE%20Package%20Hub%2015%20SP2pkg:rpm/suse/roundcubemail&distro=SUSE%20Package%20Hub%2015%20SP3pkg:rpm/suse/roundcubemail&distro=SUSE%20Package%20Hub%2015%20SP4
< 1.3.15+ 8 more
- (no CPE)range: < 1.3.15
- (no CPE)range: < 1.3.15-bp152.4.3.1
- (no CPE)range: < 1.3.15-bp152.4.3.1
- (no CPE)range: < 1.5.3-bp154.2.3.1
- (no CPE)range: < 1.5.3-bp154.2.3.1
- (no CPE)range: < 1.3.15-bp152.4.3.1
- (no CPE)range: < 1.3.15-bp152.4.3.1
- (no CPE)range: < 1.5.3-bp154.2.3.1
- (no CPE)range: < 1.5.3-bp154.2.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- lists.opensuse.org/opensuse-security-announce/2020-09/msg00083.htmlmitrevendor-advisoryx_refsource_SUSE
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3DAXK3565NYK4OEZVTW6S5LEVIDQEY2E/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OBLUQRIBAMEQVBO6GUZECCHJDJIWCYFU/mitrevendor-advisoryx_refsource_FEDORA
- github.com/roundcube/roundcubemail/commit/a71bf2e8d4a64ff2c83fdabc1e8cb0c045a41ef4mitrex_refsource_CONFIRM
- github.com/roundcube/roundcubemail/commit/d44ca2308a96576b88d6bf27528964d4fe1a6b8bmitrex_refsource_MISC
- github.com/roundcube/roundcubemail/releases/tag/1.3.15mitrex_refsource_CONFIRM
- github.com/roundcube/roundcubemail/releases/tag/1.4.8mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.