CVE-2016-4552: XSS
Published Dec 20, 2016
·Updated
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message.
Affected Software
1 affected component
Roundcube Webmail=1.2-rc
Event History
Dec 20, 2016
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4552?
CVE-2016-4552 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
2
How do I fix CVE-2016-4552?
To fix CVE-2016-4552, upgrade Roundcube Webmail to version 1.2.0 or later where the vulnerability has been patched.
3
What type of vulnerability is CVE-2016-4552?
CVE-2016-4552 is a cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2016-4552?
Users of Roundcube Webmail versions prior to 1.2.0 are affected by CVE-2016-4552.
5
What can attackers achieve with CVE-2016-4552?
Attackers can inject arbitrary web scripts or HTML into e-mail messages, potentially compromising user security.