4.3
CVSSv2

CVE-2021-46144

Published: 06/01/2022 Updated: 01/04/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Roundcube prior to 1.4.13 and 1.5.x prior to 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

roundcube roundcube

debian debian linux 9.0

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

It was discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not properly sanitize HTML messages This would allow an attacker to perform Cross-Site Scripting (XSS) attacks For the oldstable distribution (buster), this problem has been fixed in version 1317+dfsg1-1~deb10u2 For the stable distribution (bullsey ...