Medium severity6.1NVD Advisory· Published Jun 7, 2024· Updated Jun 17, 2026
CVE-2024-37384
CVE-2024-37384
Description
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/roundcube/roundcubemail/commit/cde4522c5c95f13c6aeeb1600ab17e5067a536f7nvdPatch
- github.com/roundcube/roundcubemail/releases/tag/1.5.7nvdRelease Notes
- github.com/roundcube/roundcubemail/releases/tag/1.6.7nvdRelease Notes
- lists.debian.org/debian-lts-announce/2024/06/msg00008.htmlnvdMailing List
News mentions
0No linked articles in our index yet.