383
VMScore

CVE-2015-5381

Published: 23/05/2017 Updated: 30/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x prior to 1.1.2 allows remote malicious users to inject arbitrary web script or HTML via the _mbox parameter to the default URI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

roundcube roundcube webmail 1.1.1

roundcube webmail 1.1

Vendor Advisories

Debian Bug report logs - #857473 roundcube: CVE-2017-6820: XSS issue in handling of a style tag inside of an svg element Package: src:roundcube; Maintainer for src:roundcube is Debian Roundcube Maintainers <pkg-roundcube-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: ...
Debian Bug report logs - #791643 roundcube: CVE-2015-5381 CVE-2015-5382 CVE-2015-5383 Package: src:roundcube; Maintainer for src:roundcube is Debian Roundcube Maintainers <pkg-roundcube-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 7 Jul 2015 05:03:02 UTC Seve ...