CVE-2011-2937: XSS

Published Aug 18, 2011
·
Updated

An XSS flaw was reported [1] in roundcube's message handling functionality. It has been fixed [2] upstream in r5037.

[1] http://trac.roundcube.net/ticket/1488030 [2] http://trac.roundcube.net/changeset/5037

Other sources

Cross-site scripting (XSS) vulnerability in the UI messages functionality in Roundcube Webmail before 0.5.4 allows remote attackers to inject arbitrary web script or HTML via the mbox parameter to the default URI.

MITRE

Affected Software

26 affected componentsFixes available
redhat/roundcube<0.5.4
0.5.4
Roundcube Webmail=0.5.2
Roundcube Webmail=0.1-rc1
Roundcube Webmail=0.4
Roundcube Webmail<=0.5.3
Roundcube Webmail=0.1
Roundcube Webmail=0.1-beta2
Roundcube Webmail=0.1-beta
Roundcube Webmail=0.3-rc1
Roundcube Webmail=0.5-rc
Roundcube Webmail=0.2-alpha
Roundcube Webmail=0.1-rc2
Roundcube Webmail=0.3-beta
Roundcube Webmail=0.5-beta
Roundcube Webmail=0.4.2
Roundcube Webmail=0.5.1
Roundcube Webmail=0.3
Roundcube Webmail=0.1.1
Roundcube Webmail=0.4-beta
Roundcube Webmail=0.1-alpha
Roundcube Webmail=0.4.1
Roundcube Webmail=0.2
Roundcube Webmail=0.2-beta
Roundcube Webmail=0.3.1
Roundcube Webmail=0.5
Roundcube Webmail=0.2.1

Event History

Sep 21, 2011
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2011-2937?

CVE-2011-2937 has been classified as a moderate severity Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail.

2

How do I fix CVE-2011-2937?

To fix CVE-2011-2937, update your Roundcube Webmail to version 0.5.4 or later.

3

Which versions of Roundcube are affected by CVE-2011-2937?

CVE-2011-2937 affects Roundcube Webmail versions 0.5.2, 0.5.3, 0.5, and earlier.

4

What type of attack can CVE-2011-2937 be used for?

CVE-2011-2937 can be exploited for Cross-Site Scripting (XSS) attacks, allowing attackers to execute scripts in the users' browsers.

5

Is there a patch available for CVE-2011-2937?

Yes, a patch for CVE-2011-2937 has been implemented and is included in Roundcube version 0.5.4 and newer.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203