4.3
CVSSv2

CVE-2017-6820

Published: 12/03/2017 Updated: 30/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

rcube_utils.php in Roundcube prior to 1.1.8 and 1.2.x prior to 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element.

Vulnerable Product Search on Vulmon Subscribe to Product

roundcube webmail

roundcube webmail 1.2.3

roundcube webmail 1.2.2

roundcube webmail 1.2.1

roundcube webmail 1.2.0

Vendor Advisories

Debian Bug report logs - #857473 roundcube: CVE-2017-6820: XSS issue in handling of a style tag inside of an svg element Package: src:roundcube; Maintainer for src:roundcube is Debian Roundcube Maintainers <pkg-roundcube-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: ...
It has been discovered that rcube_utilsphp in Roundcube before 118 and before 124 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element ...