Roundcube Webmail Attached HTML Cross-Site Scripting

Strike ID:
E18-5op21
CVSS:
6.1 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
False Positive:
t
Variants:
3
Year:
2018

Description

This strike exploits a cross-site scripting vulnerability in Roundcube Webmail. The vulnerability is due to improper parsing when verifying attached HTML documents for script tags which can be bypassed by using a certain sequence of HTML tags. By exploiting this flaw, an attacker may be able to execute malicious scripts in the victim's browser which may lead to account hijacking.

CVE

References