Roundcube Webmail Cross-Site Scripting (CVE-2023-5631)

Related Vulnerabilities: CVE-2023-5631  

Check Point Reference: CPAI-2023-1347 Date Published: 6 Dec 2023 Severity: Medium Last Updated: Wednesday 06 December, 2023 Source: Industry Reference:CVE-2023-5631
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable? Roundcube Webmail prior to 1.4.15
Roundcube Webmail 1.5.0 and later, prior to 1.5.5
Roundcube Webmail 1.6.0 and later, prior to 1.6.4 Vulnerability Description A cross-site scripting vulnerability exists in Roundcube Webmail. Successful exploitation of this vulnerability would allow remote attackers to inject arbitrary web script into the affected system.