Medium severity6.1NVD Advisory· Published Nov 6, 2023· Updated Jun 17, 2026
CVE-2023-47272
CVE-2023-47272
Description
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: <1.5.6, <1.6.5
- osv-coords4 versionspkg:bitnami/roundcubepkg:rpm/opensuse/roundcubemail&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/roundcubemail&distro=openSUSE%20Tumbleweedpkg:rpm/suse/roundcubemail&distro=SUSE%20Package%20Hub%2015%20SP5
>= 1.5.0, < 1.5.6+ 3 more
- (no CPE)range: >= 1.5.0, < 1.5.6
- (no CPE)range: < 1.6.7-bp155.2.9.1
- (no CPE)range: < 1.6.5-1.1
- (no CPE)range: < 1.6.7-bp155.2.9.1
Patches
Vulnerability mechanics
References
8- github.com/roundcube/roundcubemail/commit/5ec496885e18ec6af956e8c0d627856c2257ba2dnvdPatch
- lists.debian.org/debian-lts-announce/2023/12/msg00005.htmlnvdThird Party Advisory
- www.debian.org/security/2023/dsa-5572nvdThird Party Advisory
- github.com/roundcube/roundcubemail/releases/tag/1.5.6nvdRelease Notes
- github.com/roundcube/roundcubemail/releases/tag/1.6.5nvdRelease Notes
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GILSR762MJB3BNJOVOCMW2JXEPV46IIQ/nvdMailing List
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YFRGBPET73URF6364CI547ZVWQESJLGK/nvdMailing List
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z4F4DUA3Q46ZVB2RD7BFP4XMNS4RYFFQ/nvdMailing List
News mentions
0No linked articles in our index yet.