CVE-2015-5381: XSS
Published May 23, 2017
·Updated
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the mbox parameter to the default URI.
Affected Software
4 affected components
Roundcube Roundcube Webmail=1.1.1
Roundcube Webmail=1.1
Roundcube Webmail=1.1-beta
Roundcube Webmail=1.1-rc
Remediation
Patch Available
Patch Available
Patch Available
Event History
May 23, 2017
CVE Published
via MITRE·03:56 AM
Data Sourced
via MITRE·03:56 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5381?
CVE-2015-5381 is classified as a medium severity vulnerability due to its potential for exploitation via cross-site scripting.
2
How do I fix CVE-2015-5381?
To fix CVE-2015-5381, upgrade Roundcube Webmail to version 1.1.2 or later.
3
What versions of Roundcube Webmail are affected by CVE-2015-5381?
CVE-2015-5381 affects Roundcube Webmail versions 1.1.1 and earlier.
4
What type of vulnerability is CVE-2015-5381?
CVE-2015-5381 is a cross-site scripting (XSS) vulnerability.
5
What input parameter is exploited in CVE-2015-5381?
CVE-2015-5381 is exploited through the _mbox input parameter in the re-mail.php script.