Unrated severityNVD Advisory· Published Jun 24, 2021· Updated Aug 4, 2024
CVE-2020-18671
CVE-2020-18671
Description
Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php.
Affected products
4- Roundcube Mail/Roundcube Maildescription
- osv-coords3 versionspkg:bitnami/roundcubepkg:rpm/suse/roundcubemail&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/roundcubemail&distro=SUSE%20Package%20Hub%2015%20SP2
< 1.4.4+ 2 more
- (no CPE)range: < 1.4.4
- (no CPE)range: < 1.3.16-bp151.4.6.1
- (no CPE)range: < 1.3.16-bp152.4.6.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/roundcube/roundcubemail/issues/7406mitrex_refsource_MISC
- lorexxar.cn/2020/06/10/roundcube-mail-xss/mitrex_refsource_MISC
- roundcube.net/news/2020/06/02/security-updates-1.4.5-and-1.3.12mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.