First published: Tue Feb 03 2009(Updated: )
Cross-site scripting (XSS) vulnerability in RoundCube Webmail (roundcubemail) 0.2 stable allows remote attackers to inject arbitrary web script or HTML via the background attribute embedded in an HTML e-mail message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
barnraiser AROUNDMe | =0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0413 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2009-0413, upgrade to a more recent, secure version of RoundCube Webmail that has addressed this vulnerability.
CVE-2009-0413 can allow remote attackers to inject arbitrary web scripts or HTML into email messages viewed by users.
CVE-2009-0413 specifically affects RoundCube Webmail version 0.2.
While specific exploitation data for CVE-2009-0413 may vary, XSS vulnerabilities like this are commonly targeted by attackers in web applications.