VYPR
Unrated severityNVD Advisory· Published Nov 5, 2023· Updated Aug 2, 2024

CVE-2023-47272

CVE-2023-47272

Description

Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.