CVE-2013-5645: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before 0.9.3 allow user-assisted remote attackers to inject arbitrary web script or HTML via the body of a message visited in (1) new or (2) draft mode, related to compose.inc; and (3) might allow remote authenticated users to inject arbitrary web script or HTML via an HTML signature, related to saveidentity.inc.
Affected Software
Remediation
Event History
Frequently Asked Questions
What are the potential impacts of CVE-2013-5645?
CVE-2013-5645 allows remote attackers to inject arbitrary web scripts or HTML via user-assisted actions, potentially compromising user data.
How can I mitigate CVE-2013-5645 in Roundcube Webmail?
Mitigation for CVE-2013-5645 involves upgrading to Roundcube Webmail version 0.9.3 or later, which contains patches for these vulnerabilities.
What versions of Roundcube Webmail are affected by CVE-2013-5645?
CVE-2013-5645 affects all versions of Roundcube Webmail prior to 0.9.3.
Is user interaction required to exploit CVE-2013-5645?
Yes, CVE-2013-5645 exploits require user interaction to execute the malicious script.
What type of vulnerability is CVE-2013-5645 categorized as?
CVE-2013-5645 is categorized as a cross-site scripting (XSS) vulnerability.