CVE-2018-19206: XSS
steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2018-19206.
What is the severity of CVE-2018-19206?
The severity of CVE-2018-19206 is medium with a severity value of 6.1.
What is the affected software?
The affected software is Roundcube Webmail versions up to (but not including) 1.3.8.
How can I fix CVE-2018-19206?
To fix CVE-2018-19206, update your Roundcube Webmail installation to version 1.3.8 or higher.
Where can I find more information about CVE-2018-19206?
You can find more information about CVE-2018-19206 in the Roundcube news release and the GitHub issues and commit links provided: [Roundcube News Release](https://roundcube.net/news/2018/10/26/update-1.3.8-released), [GitHub Issues](https://github.com/roundcube/roundcubemail/issues/6410), [GitHub Commit](https://github.com/roundcube/roundcubemail/commit/102fbf1169116fef32a940b9fb1738bc45276059).