CVE-2016-4068: XSS
Published Apr 13, 2017
·Updated
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.
Affected Software
11 affected components
openSUSE Leap=42.1
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Roundcube Roundcube Webmail=1.1.1
Roundcube Roundcube Webmail=1.1.2
Roundcube Roundcube Webmail=1.1.3
Roundcube Webmail<=1.0.8
Roundcube Webmail=1.1
Roundcube Webmail=1.1-beta
Roundcube Webmail=1.1-rc
Roundcube Webmail=1.1.4
Remediation
Event History
Apr 13, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4068?
CVE-2016-4068 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2016-4068?
To fix CVE-2016-4068, update Roundcube Webmail to version 1.0.9 or 1.1.5 or later.
3
Which versions of Roundcube are affected by CVE-2016-4068?
CVE-2016-4068 affects Roundcube Webmail versions prior to 1.0.9 and 1.1.x before 1.1.5.
4
Can CVE-2016-4068 be exploited by remote attackers?
Yes, CVE-2016-4068 allows remote attackers to inject arbitrary web scripts or HTML.
5
What type of vulnerability is CVE-2016-4068?
CVE-2016-4068 is a Cross-site Scripting (XSS) vulnerability.