CVE-2012-3507: XSS
Cross-site scripting (XSS) vulnerability in program/steps/mail/func.inc in RoundCube Webmail before 0.8.0, when using the Larry skin, allows remote attackers to inject arbitrary web script or HTML via the email message subject.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3507?
CVE-2012-3507 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2012-3507?
To mitigate CVE-2012-3507, it is recommended to upgrade RoundCube Webmail to version 0.8.0 or later.
Which versions of RoundCube Webmail are affected by CVE-2012-3507?
CVE-2012-3507 affects RoundCube Webmail versions prior to 0.8.0, including versions up to 0.7.3.
What type of vulnerability is CVE-2012-3507?
CVE-2012-3507 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts.
In which component of RoundCube Webmail does CVE-2012-3507 exist?
CVE-2012-3507 exists in the program/steps/mail/func.inc file when using the Larry skin.