CVE-2015-1433: XSS
Published Feb 3, 2015
·Updated
program/lib/Roundcube/rcubewashtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.
Affected Software
4 affected components
Roundcube Webmail<=1.0.4
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Fedoraproject Fedora=21
Remediation
Patch Available
Event History
Feb 3, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1433?
CVE-2015-1433 has a high severity rating due to its potential to allow remote attackers to conduct cross-site scripting attacks.
2
How do I fix CVE-2015-1433?
To fix CVE-2015-1433, you should upgrade your Roundcube installation to version 1.0.5 or later.
3
What versions of Roundcube are affected by CVE-2015-1433?
CVE-2015-1433 affects all versions of Roundcube prior to 1.0.5.
4
Can I prevent CVE-2015-1433 if I don't use Roundcube?
If you do not use Roundcube, you are not affected by CVE-2015-1433, as it is specific to that software.
5
What types of attacks can CVE-2015-1433 enable?
CVE-2015-1433 can enable attackers to execute cross-site scripting (XSS) attacks through unquoted strings in email style attributes.