CVE-2015-8793: XSS
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the mbox parameter in a mail task to the default URL, a different vulnerability than CVE-2011-2937.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8793?
CVE-2015-8793 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2015-8793?
To fix CVE-2015-8793, you should update Roundcube to version 1.0.6 or 1.1.2 or later.
Which versions of Roundcube are affected by CVE-2015-8793?
CVE-2015-8793 affects Roundcube versions before 1.0.6 and 1.1.x before 1.1.2.
Can CVE-2015-8793 lead to data breaches?
Yes, CVE-2015-8793 can allow attackers to inject malicious scripts, potentially leading to data breaches.
Is user input safe if using the affected Roundcube versions?
No, user input is not safe and can be exploited in the affected versions of Roundcube due to the vulnerability.