CVE-2011-2937: XSS
An XSS flaw was reported [1] in roundcube's message handling functionality. It has been fixed [2] upstream in r5037.
[1] http://trac.roundcube.net/ticket/1488030 [2] http://trac.roundcube.net/changeset/5037
Other sources
Cross-site scripting (XSS) vulnerability in the UI messages functionality in Roundcube Webmail before 0.5.4 allows remote attackers to inject arbitrary web script or HTML via the mbox parameter to the default URI.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2937?
CVE-2011-2937 has been classified as a moderate severity Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail.
How do I fix CVE-2011-2937?
To fix CVE-2011-2937, update your Roundcube Webmail to version 0.5.4 or later.
Which versions of Roundcube are affected by CVE-2011-2937?
CVE-2011-2937 affects Roundcube Webmail versions 0.5.2, 0.5.3, 0.5, and earlier.
What type of attack can CVE-2011-2937 be used for?
CVE-2011-2937 can be exploited for Cross-Site Scripting (XSS) attacks, allowing attackers to execute scripts in the users' browsers.
Is there a patch available for CVE-2011-2937?
Yes, a patch for CVE-2011-2937 has been implemented and is included in Roundcube version 0.5.4 and newer.